MEDIUM
CVE-2021-22183
CVSS
5.4
Description
An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.
Summary dbcve.org
GitLab versions 11.8 and later contain a stored cross-site scripting (XSS) vulnerability in the epics feature. An attacker can inject malicious JavaScript code into the epics page content, which executes when other users view or interact with the crafted epic, allowing session hijacking, credential theft, or defacement.
Mitigation
Upgrade GitLab to the latest stable version that includes the security patch for CVE-2021-22183. As a temporary measure, restrict access to the epics feature and educate users about not clicking suspicious links.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.84%
Probability of exploitation in next 30 days
56.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.