MEDIUM

CVE-2020-10092

Gitlab GitLab 2020-03-13 CVSS v3.1
CVSS
6.1

Description

GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

Summary dbcve.org

GitLab versions 12.1 through 12.8.1 contain a cross-site scripting (XSS) vulnerability in the Grafana integration view. The vulnerability allows attackers to inject malicious scripts through unsanitized input in the Grafana integration component.

Mitigation

Upgrade GitLab to version 12.8.2 or later to receive the security patch. Alternatively, disable the Grafana integration if upgrading is not immediately feasible.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE