MEDIUM

CVE-2021-22196

Gitlab GitLab 2021-04-02 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability in GitLab CE/EE versions 13.4 and later allows attackers to inject malicious scripts via a crafted branch name in merge requests. The payload is stored and executes when other users view the affected merge request.

Mitigation

Update GitLab to the patched version released to address this vulnerability. Additionally, limit branch creation privileges to trusted users and implement Content Security Policy headers as a defense-in-depth measure.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.94%
Probability of exploitation in next 30 days
59.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE