HIGH
CVE-2020-10087
CVSS
7.5
Description
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.
Summary dbcve.org
GitLab before 12.8.2 failed to proxy badge images, causing them to load directly from external sources instead of through GitLab's server. This leaked users' IP addresses to external badge providers and triggered mixed content warnings since external images could be loaded over HTTP on HTTPS GitLab instances.
Mitigation
Upgrade GitLab to version 12.8.2 or later, which implements proper proxying of badge image requests to prevent IP address disclosure.
EPSS Score
1.17%
Probability of exploitation in next 30 days
66.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.