CVE-2020-13262: Code Injection
Published Jun 19, 2020
·Updated
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
Affected Software
6 affected components
GitLab GitLab>=12.9.0<12.9.8
GitLab GitLab>=12.9.0<12.9.8
GitLab GitLab>=12.10.0<12.10.7
GitLab GitLab>=12.10.0<12.10.7
GitLab GitLab=13.0.0
GitLab GitLab=13.0.0
Event History
Jun 19, 2020
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13262?
CVE-2020-13262 is classified as a critical vulnerability due to its potential for client-side code injection.
2
How do I fix CVE-2020-13262?
To mitigate CVE-2020-13262, upgrade to the latest GitLab version 12.9.9, 12.10.8, or version 13.0.2 or later.
3
What are the affected versions in CVE-2020-13262?
CVE-2020-13262 affects GitLab CE/EE versions from 12.9.0 to 12.9.8, 12.10.0 to 12.10.7, and 13.0.0.
4
What is the impact of CVE-2020-13262?
The impact of CVE-2020-13262 can lead to unauthorized PUT requests being executed on behalf of other users.
5
Is CVE-2020-13262 exploitable remotely?
Yes, CVE-2020-13262 is exploitable remotely through specially crafted Mermaid payloads.