MEDIUM

CVE-2021-22185

Gitlab GitLab 2021-03-24 CVSS v3.1
CVSS
5.4

Description

Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability exists in GitLab wikis starting from version 13.8 due to insufficient input sanitization. Attackers can inject malicious JavaScript code through specially-crafted commits to a wiki page, which will execute when other users view the compromised wiki content.

Mitigation

Update GitLab to the patched version provided by the vendor. As a temporary measure, restrict wiki write access to trusted users and validate all wiki content before publication.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.81%
Probability of exploitation in next 30 days
55.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE