CVE-2020-13321

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/09/2020
Last modified:
02/10/2020

Description

A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* 12.10.13 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* 13.0.0 (including) 13.0.8 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* 13.1.0 (including) 13.1.2 (excluding)