MEDIUM

CVE-2020-26407

Gitlab GitLab 2020-12-10 CVSS v3.1
CVSS
5.4

Description

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

Summary dbcve.org

A stored XSS vulnerability in GitLab CE/EE allows attackers to inject malicious JavaScript code through project import functionality. When other users view the imported project, the XSS payload executes in their browsers, potentially stealing session cookies or performing actions on behalf of victims.

Mitigation

Upgrade GitLab to version 13.4.8 or later, 13.5.6 or later, or 13.6.3 or later. Alternatively, disable project import functionality until the patch can be applied.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.73%
Probability of exploitation in next 30 days
52.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE