An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.
2020-09-30T18:15:19.833
2024-11-21T05:01:02.723
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 12.10.13 | Yes |
Application | gitlab | gitlab | < 13.0.8 | Yes |
Application | gitlab | gitlab | < 13.1.2 | Yes |