MEDIUM
CVE-2021-39946
CVSS
5.4
Description
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
Summary dbcve.org
Improper neutralization of user input in GitLab's emoji HTML code generation allowed an attacker to inject malicious scripts via XSS. The vulnerability affects GitLab CE/EE versions 14.3 through 14.3.6, 14.4 through 14.4.4, and 14.5 through 14.5.2.
Mitigation
Upgrade GitLab to a patched version beyond 14.5.2 to resolve the improper input sanitization in emoji HTML rendering.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.04%
Probability of exploitation in next 30 days
62.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.