Medium severity6.1NVD Advisory· Published Mar 13, 2020· Updated Jun 17, 2026
CVE-2020-10076
CVE-2020-10076
Description
GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.1.0,<=12.8.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.1.0,<=12.8.1
- (no CPE)range: 12.1 - 12.8.1
- GitLab/GitLabdescription
Patches
Vulnerability mechanics
References
2- about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/nvdRelease NotesVendor Advisory
- about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/index.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.