A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
{ "cpes": [ "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*", "cpe:2.3:a:gitlab:gitlab:12.4:*:*:*:*:*:*:*", "cpe:2.3:a:gitlab:gitlab:12.4:*:*:*:enterprise:*:*:*", "cpe:2.3:a:gitlab:gitlab:13.5:*:*:*:*:*:*:*", "cpe:2.3:a:gitlab:gitlab:13.5:*:*:*:enterprise:*:*:*", "cpe:2.3:a:gitlab:gitlab:13.6:*:*:*:*:*:*:*", "cpe:2.3:a:gitlab:gitlab:13.6:*:*:*:enterprise:*:*:*" ], "severity": "Medium" }