MEDIUM
CVE-2020-26407
CVSS
5.4
Description
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
Summary dbcve.org
A stored XSS vulnerability in GitLab CE/EE allows attackers to inject malicious JavaScript code through project import functionality. When other users view the imported project, the XSS payload executes in their browsers, potentially stealing session cookies or performing actions on behalf of victims.
Mitigation
Upgrade GitLab to version 13.4.8 or later, 13.5.6 or later, or 13.6.3 or later. Alternatively, disable project import functionality until the patch can be applied.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.73%
Probability of exploitation in next 30 days
52.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.