Vulnerability Database
Blog
FAQ
Docs
CVE-2020-12276
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2020-12276
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-12276.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-12276
Aliases
BIT-gitlab-2020-12276
Related
UBUNTU-CVE-2020-12276
Published
2020-04-29T17:15:11Z
Modified
2024-10-11T10:10:45Z
Severity
4.8 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.
References
https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/
Affected packages
Git
/
gitlab.com/gitlab-org/gitlab
Affected ranges
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Introduced
42f94770886f513d3b1c000c8c3190d776539b02
Fixed
8c3dbc944a2af1e1c5ae9145fc9991d38b7abbb3
CVE-2020-12276 - OSV