HIGH
CVE-2020-13340
CVSS
8.7
Description
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
Summary dbcve.org
Stored XSS vulnerability in GitLab's CI Job Log feature allows attackers to inject malicious JavaScript that executes when users view CI job logs. The vulnerability exists in all versions prior to 13.2.10, 13.3.7, and 13.4.2.
Mitigation
Upgrade GitLab to version 13.2.10, 13.3.7, 13.4.2 or later to patch the stored XSS in CI job logs.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
68.64%
Probability of exploitation in next 30 days
99.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.