HIGH

CVE-2021-22230

Gitlab GitLab 2021-07-07 CVSS v3.1
CVSS
7.2

Description

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

Summary dbcve.org

Cross-site scripting (XSS) vulnerability in GitLab's merge request code rendering. The application fails to properly sanitize/escape code content when rendering merge requests, allowing an attacker to inject malicious JavaScript that executes in the browsers of users viewing the affected merge request.

Mitigation

Upgrade GitLab to versions 13.11.7, 13.12.7, or 14.0.3 or later which contain the security fix. Alternatively, restrict merge request creation permissions to trusted users until patching can be completed.

EPSS Score

0.97%
Probability of exploitation in next 30 days
60.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE