CVE-2020-10087

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/03/2020
Last modified:
12/07/2022

Description

GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 12.8.1 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.8.1 (including)