MEDIUM
CVE-2021-22185
CVSS
5.4
Description
Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki
Summary dbcve.org
A stored cross-site scripting (XSS) vulnerability exists in GitLab wikis starting from version 13.8 due to insufficient input sanitization. Attackers can inject malicious JavaScript code through specially-crafted commits to a wiki page, which will execute when other users view the compromised wiki content.
Mitigation
Update GitLab to the patched version provided by the vendor. As a temporary measure, restrict wiki write access to trusted users and validate all wiki content before publication.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.81%
Probability of exploitation in next 30 days
55.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.