CVE-2020-26407: XSS
Published Dec 10, 2020
·Updated
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
Affected Software
6 affected components
GitLab GitLab>=12.4.0<13.4.7
GitLab GitLab>=12.4.0<13.4.7
GitLab GitLab>=13.5.0<13.5.5
GitLab GitLab>=13.5.0<13.5.5
GitLab GitLab>=13.6.0<13.6.2
GitLab GitLab>=13.6.0<13.6.2
Event History
Dec 10, 2020
CVE Published
via MITRE·05:16 AM
Data Sourced
via MITRE·05:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26407?
CVE-2020-26407 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2020-26407?
To fix CVE-2020-26407, upgrade GitLab CE/EE to versions 13.4.7, 13.5.5, or 13.6.2 or later.
3
What systems are affected by CVE-2020-26407?
CVE-2020-26407 affects GitLab CE/EE versions 12.4 through 13.4.6, 13.5 through 13.5.4, and 13.6 through 13.6.1.
4
What kind of attack can be performed using CVE-2020-26407?
CVE-2020-26407 allows an attacker to perform cross-site scripting (XSS) by importing a malicious project.
5
Is user interaction required for exploiting CVE-2020-26407?
Yes, user interaction is required as the victim must import the malicious project.