MEDIUM
CVE-2020-13285
CVSS
5.4
Description
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
Summary dbcve.org
A cross-site scripting (XSS) vulnerability exists in GitLab's issue reference number tooltip. User-supplied input in issue references is not properly sanitized before being rendered in the tooltip, allowing an attacker to inject malicious JavaScript code that executes in the context of other users' browsers.
Mitigation
Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later. These versions contain the patch that properly sanitizes issue reference tooltips to prevent XSS attacks.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.01%
Probability of exploitation in next 30 days
61.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.