CVE Vulnerabilities

CVE-2020-10087

Published: Mar 13, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab*12.8.1 (including)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuupstream*
GitlabUbuntuxenial*

References