MEDIUM
CVE-2020-13267
CVSS
6.1
Description
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
Summary dbcve.org
A stored Cross-Site Scripting vulnerability in the Metrics Dashboard of GitLab CE/EE versions 12.8 through 13.0.1 allows attackers to inject malicious JavaScript payloads that execute in the browsers of users viewing the affected dashboard, enabling session hijacking, credential theft, or defacement.
Mitigation
Upgrade GitLab to the patched version (13.0.2 or later). Until then, restrict access to the Metrics Dashboard feature and implement Content Security Policy headers to mitigate XSS execution.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.75%
Probability of exploitation in next 30 days
76.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.