First published: Tue Oct 06 2020(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.8.0<13.2.10 | |
GitLab | >=10.8.0<13.2.10 | |
GitLab | >=13.3.0<13.3.7 | |
GitLab | >=13.3.0<13.3.7 | |
GitLab | >=13.4.0<13.4.2 | |
GitLab | >=13.4.0<13.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13345 has been classified as a medium severity vulnerability due to its potential for causing reflected cross-site scripting attacks.
To fix CVE-2020-13345, update GitLab to the latest version available for your edition that addresses this vulnerability.
Reflected XSS in CVE-2020-13345 refers to a type of attack where malicious scripts are injected into a web application and executed in the context of a user's session.
CVE-2020-13345 affects all GitLab versions from 10.8.0 up to 13.4.2.
Mitigating CVE-2020-13345 without upgrading is challenging and not recommended, as fixing this requires addressing code that allows for reflected XSS.