Lucene search

K
osvGoogleOSV:CVE-2020-26407
HistoryDec 10, 2020 - 6:15 a.m.

CVE-2020-26407

2020-12-1006:15:13
Google
osv.dev
4
xss
gitlab
ce/ee
cross-site scripting
vulnerability
malicious project

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

26.7%

A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

26.7%