HIGH
CVE-2021-22230
CVSS
7.2
Description
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.
Summary dbcve.org
Cross-site scripting (XSS) vulnerability in GitLab's merge request code rendering. The application fails to properly sanitize/escape code content when rendering merge requests, allowing an attacker to inject malicious JavaScript that executes in the browsers of users viewing the affected merge request.
Mitigation
Upgrade GitLab to versions 13.11.7, 13.12.7, or 14.0.3 or later which contain the security fix. Alternatively, restrict merge request creation permissions to trusted users until patching can be completed.
EPSS Score
0.97%
Probability of exploitation in next 30 days
60.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.