MEDIUM
CVE-2021-22199
CVSS
5.4
Description
An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.
Summary dbcve.org
GitLab versions 12.9 and later are vulnerable to stored XSS when scoped labels are used. An attacker can inject malicious JavaScript through label names that executes in the browsers of other users viewing those labels.
Mitigation
Upgrade GitLab to the latest patched version. Until then, restrict or disable scoped label creation for untrusted users.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.79%
Probability of exploitation in next 30 days
54.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.