MEDIUM

CVE-2021-39887

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
5.4

Description

A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.

Summary dbcve.org

A stored Cross-Site Scripting (XSS) vulnerability in GitLab Flavored Markdown rendering in GitLab CE/EE versions 8.4 and above allows attackers to inject malicious JavaScript payloads into stored markdown content. When victims view the crafted markdown, the embedded script executes in their browser context.

Mitigation

Upgrade GitLab to the patched version released for this CVE. Until patched, restrict or sanitize user-submitted markdown content in affected GitLab instances.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.86%
Probability of exploitation in next 30 days
57.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE