MEDIUM
CVE-2020-10092
CVSS
6.1
Description
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.
Summary dbcve.org
GitLab versions 12.1 through 12.8.1 contain a cross-site scripting (XSS) vulnerability in the Grafana integration view. The vulnerability allows attackers to inject malicious scripts through unsanitized input in the Grafana integration component.
Mitigation
Upgrade GitLab to version 12.8.2 or later to receive the security patch. Alternatively, disable the Grafana integration if upgrading is not immediately feasible.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.69%
Probability of exploitation in next 30 days
51.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.