First published: Fri Mar 13 2020(Updated: )
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <=12.8.1 | |
GitLab | <=12.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10087 has a medium severity rating due to its potential for information disclosure.
To fix CVE-2020-10087, upgrade your GitLab instance to version 12.8.2 or later.
CVE-2020-10087 affects GitLab community and enterprise editions prior to version 12.8.2.
CVE-2020-10087 can leak user IP addresses due to the improper handling of badge images.
Yes, CVE-2020-10087 causes mixed content warnings as a result of badge images not being proxied.