MEDIUM
CVE-2020-10075
CVSS
6.1
Description
GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.
Summary dbcve.org
HTML Injection vulnerability in GitLab 12.5 through 12.8.1 where an error header does not properly escape user-controlled input, allowing injection of malicious HTML content into the header response.
Mitigation
Upgrade to GitLab 12.8.2 or later, and implement proper output encoding/escaping of all user input before including it in HTTP headers.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.73%
Probability of exploitation in next 30 days
52.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.