HIGH

CVE-2020-10087

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
7.5

Description

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

Summary dbcve.org

GitLab before 12.8.2 failed to proxy badge images, causing them to load directly from external sources instead of through GitLab's server. This leaked users' IP addresses to external badge providers and triggered mixed content warnings since external images could be loaded over HTTP on HTTPS GitLab instances.

Mitigation

Upgrade GitLab to version 12.8.2 or later, which implements proper proxying of badge image requests to prevent IP address disclosure.

EPSS Score

1.17%
Probability of exploitation in next 30 days
66.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE