MEDIUM

CVE-2020-13283

Gitlab GitLab 2020-08-13 CVSS v3.1
CVSS
5.4

Description

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability in GitLab allows authenticated users to inject malicious JavaScript code through milestone titles. When other users view the issues list, the injected payload executes in their browsers, potentially allowing session hijacking or data theft.

Mitigation

Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later to patch the vulnerability. Until upgraded, restrict milestone creation permissions and warn users not to click on suspicious milestone links.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.85%
Probability of exploitation in next 30 days
56.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE