CVE-2020-10087: GitLab
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.
Affected products
- GitLab GitLab: up to and including 12.8.1
Published 2020-03-13. Last modified 2026-06-17.