MEDIUM
CVE-2020-10091
CVSS
6.1
Description
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
Summary dbcve.org
This is a stored cross-site scripting (XSS) vulnerability in GitLab's file viewing functionality. Affected versions (9.3 through 12.8.1) fail to properly sanitize certain file types when rendered, allowing attackers to inject malicious JavaScript that executes in the browser of users viewing those files.
Mitigation
Upgrade GitLab to version 12.8.2 or later to receive the patch. Until then, restrict or disable file preview for untrusted file types in repositories.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.69%
Probability of exploitation in next 30 days
51.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.