MEDIUM

CVE-2020-13271

Gitlab GitLab 2020-06-10 CVSS v3.1
CVSS
6.1

Description

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

Summary dbcve.org

A stored Cross-Site Scripting vulnerability in GitLab's blobs API allows attackers to inject malicious JavaScript code that executes in the browsers of users who view affected blobs. This affects all GitLab CE/EE versions prior to 13.0.2.

Mitigation

Upgrade GitLab to version 13.0.2 or later to patch this vulnerability.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

1.53%
Probability of exploitation in next 30 days
73.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE