CVE-2020-26407

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/12/2020
Last modified:
11/12/2020

Description

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 12.4.0 (including) 13.4.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 12.4.0 (including) 13.4.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 13.5.0 (including) 13.5.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.5.0 (including) 13.5.5 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 13.6.0 (including) 13.6.2 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.6.0 (including) 13.6.2 (excluding)