Vulnerability record · CVE-2020-13340 · published 8 October 2020
CVE-2020-13340: GitLab stored XSS in CI job log
Gitlab · Gitlab
GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2 contain a stored cross-site scripting flaw in the CI job log. Because the injected script persists in the job log and is served to other users viewing it, the flaw can compromise accounts and sessions beyond the original submitter.
Description
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Automated analysis
high priorityHigh CVSS (8.7) with scope change and very high EPSS probability, though no KEV listing or documented exploitation.
What it is
GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2 contain a stored cross-site scripting flaw in the CI job log. Because the injected script persists in the job log and is served to other users viewing it, the flaw can compromise accounts and sessions beyond the original submitter.
Impact
An attacker can execute arbitrary script in the browser of any user who views the affected CI job log, potentially stealing session tokens or acting as that user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the GitLab web interface by a user who can influence CI job log content; the vector requires low privileges (PR:L) and user interaction (UI:R) from the victim who views the log.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at 0.686 (99.3rd percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade GitLab to 13.2.10, 13.3.7, 13.4.2 or later, which contain the fix.
- Restrict who can create or modify CI jobs and job log output to trusted users.
- Sanitize or escape untrusted content written into CI job logs.
- Apply a Content Security Policy to reduce script execution impact in the GitLab UI.
Detection
- Review CI job logs for embedded script tags or HTML event handlers.
- Monitor GitLab access logs for anomalous requests to job log endpoints.
- Alert on user reports of unexpected script execution or session anomalies after viewing job logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13340.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/233473 | Broken Link |
| https://hackerone.com/reports/950190 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13340.json | Third Party Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/233473 | Broken Link |
| https://hackerone.com/reports/950190 | Permissions RequiredThird Party Advisory |
Track CVE-2020-13340 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13340), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.