MEDIUM
CVE-2021-22220
CVSS
5.4
Description
An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.
Summary dbcve.org
GitLab versions 13.10 and later contain a stored cross-site scripting (XSS) vulnerability in the blob viewer component of notebooks. Attackers can inject malicious JavaScript that executes when users view notebook content, allowing session hijacking or data theft.
Mitigation
Upgrade GitLab to the latest available version or to a patched version for your release branch. Review notebook blob viewer content for any suspicious injected scripts.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.74%
Probability of exploitation in next 30 days
53.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.