PT-2020-19886 · Gitlab · Gitlab Ce/Ee+1

Rioncool22

·

Published

2020-02-05

·

Updated

2024-03-06

·

CVE-2020-7971

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 11.0 through 12.7.2
Description The issue allows for cross-site scripting (XSS), which is a type of attack that can be used to steal user data or take control of user sessions.
Recommendations For GitLab EE versions 11.0 through 12.7.2, update to a version later than 12.7.2 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2020-7971
CVE-2020-7971

Affected Products

Gitlab
Gitlab Ce/Ee