CVE-2020-12276: XSS
Published Apr 29, 2020
·Updated
GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.
Affected Software
6 affected components
GitLab GitLab>=9.5.9<12.7.8
GitLab GitLab>=9.5.9<12.7.8
GitLab GitLab>=12.8.0<12.8.8
GitLab GitLab>=12.8.0<12.8.8
GitLab GitLab>=12.9.0<12.9.1
GitLab GitLab>=12.9.0<12.9.1
Event History
Apr 29, 2020
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12276?
CVE-2020-12276 has a medium severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2020-12276?
To fix CVE-2020-12276, upgrade to GitLab version 12.9.1 or later for both community and enterprise editions.
3
What software is affected by CVE-2020-12276?
CVE-2020-12276 affects GitLab versions from 9.5.9 through 12.9, including both community and enterprise editions.
4
What type of vulnerability is CVE-2020-12276?
CVE-2020-12276 is categorized as a stored cross-site scripting (XSS) vulnerability.
5
When was CVE-2020-12276 disclosed?
CVE-2020-12276 was disclosed on March 26, 2020, alongside GitLab's security release.