MEDIUM

CVE-2020-10091

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
6.1

Description

GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

Summary dbcve.org

This is a stored cross-site scripting (XSS) vulnerability in GitLab's file viewing functionality. Affected versions (9.3 through 12.8.1) fail to properly sanitize certain file types when rendered, allowing attackers to inject malicious JavaScript that executes in the browser of users viewing those files.

Mitigation

Upgrade GitLab to version 12.8.2 or later to receive the patch. Until then, restrict or disable file preview for untrusted file types in repositories.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE