Description
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected products
- gitlab / GitLab CE/EE>=12.4 – >=12.4
- gitlab / GitLab CE/EE<13.4.7 – <13.4.7
- gitlab / GitLab CE/EE>=13.5 – >=13.5
- gitlab / GitLab CE/EE<13.5.5 – <13.5.5
- gitlab / GitLab CE/EE>=13.6 – >=13.6
- gitlab / GitLab CE/EE<13.6.2 – <13.6.2