MEDIUM

CVE-2021-22220

Gitlab GitLab 2021-06-08 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

Summary dbcve.org

GitLab versions 13.10 and later contain a stored cross-site scripting (XSS) vulnerability in the blob viewer component of notebooks. Attackers can inject malicious JavaScript that executes when users view notebook content, allowing session hijacking or data theft.

Mitigation

Upgrade GitLab to the latest available version or to a patched version for your release branch. Review notebook blob viewer content for any suspicious injected scripts.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.74%
Probability of exploitation in next 30 days
53.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE