CVE-2020-10091: XSS
Published Mar 13, 2020
·Updated
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
Affected Software
2 affected components
GitLab GitLab>=9.3.0<=12.8.1
GitLab GitLab>=9.3.0<=12.8.1
Event History
Mar 13, 2020
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10091?
CVE-2020-10091 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
2
What versions of GitLab are affected by CVE-2020-10091?
CVE-2020-10091 affects GitLab versions from 9.3.0 to 12.8.1 inclusive.
3
How can I fix CVE-2020-10091?
To fix CVE-2020-10091, you should upgrade your GitLab installation to version 12.8.2 or later.
4
What type of vulnerability is CVE-2020-10091?
CVE-2020-10091 is a cross-site scripting (XSS) vulnerability.
5
What impact does CVE-2020-10091 have on users?
CVE-2020-10091 can allow attackers to execute arbitrary JavaScript code in the context of a user's session.