CVE-2020-13269: XSS
Published Jun 10, 2020
·Updated
A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1
Affected Software
4 affected components
GitLab GitLab>=12.10.0<12.10.7
GitLab GitLab>=12.10.0<12.10.7
GitLab GitLab>=13.0.0<13.0.1
GitLab GitLab>=13.0.0<13.0.1
Event History
Jun 10, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13269?
CVE-2020-13269 has been rated as a medium severity vulnerability due to the potential for arbitrary JavaScript execution.
2
How do I fix CVE-2020-13269?
To mitigate CVE-2020-13269, it is recommended to upgrade GitLab to version 12.10.8 or 13.0.2 or later.
3
Who is affected by CVE-2020-13269?
CVE-2020-13269 affects GitLab Community Edition and Enterprise Edition versions from 12.10.0 to 12.10.7 and 13.0.0 to 13.0.1.
4
What type of vulnerability is CVE-2020-13269?
CVE-2020-13269 is a reflected Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2020-13269 lead to further attacks?
Yes, exploiting CVE-2020-13269 can enable attackers to execute arbitrary JavaScript, potentially leading to session hijacking and data theft.