MEDIUM

CVE-2020-13267

Gitlab GitLab 2020-06-10 CVSS v3.1
CVSS
6.1

Description

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

Summary dbcve.org

A stored Cross-Site Scripting vulnerability in the Metrics Dashboard of GitLab CE/EE versions 12.8 through 13.0.1 allows attackers to inject malicious JavaScript payloads that execute in the browsers of users viewing the affected dashboard, enabling session hijacking, credential theft, or defacement.

Mitigation

Upgrade GitLab to the patched version (13.0.2 or later). Until then, restrict access to the Metrics Dashboard feature and implement Content Security Policy headers to mitigate XSS execution.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

1.75%
Probability of exploitation in next 30 days
76.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE