A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
2020-12-10T06:15:13.750
2024-11-21T05:19:52.393
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 13.4.7 | Yes |
Application | gitlab | gitlab | < 13.4.7 | Yes |
Application | gitlab | gitlab | < 13.5.5 | Yes |
Application | gitlab | gitlab | < 13.5.5 | Yes |
Application | gitlab | gitlab | < 13.6.2 | Yes |
Application | gitlab | gitlab | < 13.6.2 | Yes |