{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "fixed": "12.10.13"
              },
              {
                "introduced": "13.0.0"
              },
              {
                "fixed": "13.0.8"
              },
              {
                "introduced": "13.1.0"
              },
              {
                "fixed": "13.1.2"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "ec145a327278663269837a9fbbf06aaef2517df8"
            },
            {
              "introduced": "ef3e35341f6a930af2d57979999b71457b9f72a4"
            },
            {
              "fixed": "398ac950bd5564f0fc1b928526b29c8eb7c0a18d"
            },
            {
              "introduced": "1fa237df2f46d34bd56dd8d018183c756094c2e0"
            },
            {
              "fixed": "d3d6e3f69eee5b68222674ff50b71a32a528a20c"
            }
          ],
          "repo": "https://gitlab.com/gitlab-org/gitlab",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.",
  "id": "CVE-2020-13321",
  "modified": "2026-03-13T21:46:52.403445601Z",
  "published": "2020-09-30T18:15:19.380Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13321.json"
    },
    {
      "type": "EVIDENCE",
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/25751"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
      "type": "CVSS_V3"
    }
  ]
}