MEDIUM
CVE-2020-13271
CVSS
6.1
Description
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
Summary dbcve.org
A stored Cross-Site Scripting vulnerability in GitLab's blobs API allows attackers to inject malicious JavaScript code that executes in the browsers of users who view affected blobs. This affects all GitLab CE/EE versions prior to 13.0.2.
Mitigation
Upgrade GitLab to version 13.0.2 or later to patch this vulnerability.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.53%
Probability of exploitation in next 30 days
73.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.