First published: Thu Oct 08 2020(Updated: )
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <13.2.10 | |
GitLab | <13.2.10 | |
GitLab | >=13.3.0<13.3.7 | |
GitLab | >=13.3.0<13.3.7 | |
GitLab | >=13.4.0<13.4.2 | |
GitLab | >=13.4.0<13.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13340 has a medium severity rating due to its potential to allow stored XSS attacks.
To fix CVE-2020-13340, upgrade GitLab to version 13.2.10, 13.3.7, or 13.4.2 or later.
CVE-2020-13340 affects all GitLab versions prior to 13.2.10, 13.3.7, and 13.4.2.
CVE-2020-13340 is a stored cross-site scripting (XSS) vulnerability that impacts the CI job log in GitLab.
While you can continue to use your vulnerable GitLab instance, it is highly recommended to apply the necessary patches to mitigate the risk of XSS attacks.