MEDIUM

CVE-2020-13339

Gitlab GitLab 2020-10-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only being impacted.

Summary dbcve.org

GitLab versions before 13.2.10, 13.3.7, and 13.4.2 contain a stored cross-site scripting (XSS) vulnerability in the SVG file preview functionality. When a malicious SVG file containing embedded JavaScript is uploaded and previewed by another user, the script executes in their session, potentially allowing session hijacking or actions on behalf of the victim.

Mitigation

Upgrade GitLab to version 13.2.10, 13.3.7, 13.4.2 or later. Until patched, restrict or disable SVG file uploads in the instance.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.82%
Probability of exploitation in next 30 days
55.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE