CVE-2020-13340: XSS
Published Oct 8, 2020
·Updated
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
Affected Software
6 affected components
GitLab GitLab<13.2.10
GitLab GitLab<13.2.10
GitLab GitLab>=13.3.0<13.3.7
GitLab GitLab>=13.3.0<13.3.7
GitLab GitLab>=13.4.0<13.4.2
GitLab GitLab>=13.4.0<13.4.2
Event History
Oct 8, 2020
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13340?
CVE-2020-13340 has a medium severity rating due to its potential to allow stored XSS attacks.
2
How do I fix CVE-2020-13340?
To fix CVE-2020-13340, upgrade GitLab to version 13.2.10, 13.3.7, or 13.4.2 or later.
3
Which versions of GitLab are affected by CVE-2020-13340?
CVE-2020-13340 affects all GitLab versions prior to 13.2.10, 13.3.7, and 13.4.2.
4
What type of vulnerability is CVE-2020-13340?
CVE-2020-13340 is a stored cross-site scripting (XSS) vulnerability that impacts the CI job log in GitLab.
5
Can I still use my GitLab instance if it is vulnerable to CVE-2020-13340?
While you can continue to use your vulnerable GitLab instance, it is highly recommended to apply the necessary patches to mitigate the risk of XSS attacks.