First published: Fri Jan 24 2014(Updated: )
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7316 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2013-7316, upgrade to GitLab version 6.5.0 or later, which includes a patch for this vulnerability.
CVE-2013-7316 affects GitLab versions 6.0.0 through 6.4.9.
CVE-2013-7316 enables remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
You can determine if your GitLab instance is vulnerable by checking the version to see if it is below 6.5.0.