PT-2020-13089 · Gitlab · Gitlab

Published

2020-04-29

·

Updated

2024-03-06

·

CVE-2020-12276

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 9.5.9 through 12.9
Description The issue concerns a stored XSS vulnerability in an admin notification feature. This allows for malicious code to be stored and executed when the notification is viewed by an administrator.
Recommendations For GitLab versions 9.5.9 through 12.9, update to a version that contains a fix for this issue to prevent stored XSS attacks. As a temporary workaround, consider restricting access to the admin notification feature until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-12276
CVE-2020-12276

Affected Products

Gitlab