MEDIUM

CVE-2021-22183

Gitlab GitLab 2021-03-04 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.

Summary dbcve.org

GitLab versions 11.8 and later contain a stored cross-site scripting (XSS) vulnerability in the epics feature. An attacker can inject malicious JavaScript code into the epics page content, which executes when other users view or interact with the crafted epic, allowing session hijacking, credential theft, or defacement.

Mitigation

Upgrade GitLab to the latest stable version that includes the security patch for CVE-2021-22183. As a temporary measure, restrict access to the epics feature and educate users about not clicking suspicious links.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.84%
Probability of exploitation in next 30 days
56.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE