CVE-2020-10087

HIGH

GitLab < 12.8.2 - Information Disclosure via Badge Image Proxy Bypass

Title source: llm
STIX 2.1

Description

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
gitlab/gitlab < 12.8.1 (2 CPE variants)
Published Mar 13, 2020
Tracked Since Feb 18, 2026