CVE-2020-13262
19.06.2020, 22:15
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 12.9.0 ≤ 𝑥 < 12.9.8 |
gitlab | gitlab | 12.9.0 ≤ 𝑥 < 12.9.8 |
gitlab | gitlab | 12.10.0 ≤ 𝑥 < 12.10.7 |
gitlab | gitlab | 12.10.0 ≤ 𝑥 < 12.10.7 |
gitlab | gitlab | 13.0.0 |
gitlab | gitlab | 13.0.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References