MEDIUM

CVE-2020-10078

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
6.1

Description

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability exists in the merge request submission form of GitLab versions 12.1 through 12.8.1. Attackers can inject malicious JavaScript payloads into merge request fields that persist on the page, executing in the browsers of users who view the affected merge requests.

Mitigation

Upgrade GitLab to version 12.8.2 or later. Alternatively, apply any available security patches from GitLab. Review merge request inputs for existing malicious content.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE