MEDIUM

CVE-2021-39946

Gitlab GitLab 2022-01-18 CVSS v3.1
CVSS
5.4

Description

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

Summary dbcve.org

Improper neutralization of user input in GitLab's emoji HTML code generation allowed an attacker to inject malicious scripts via XSS. The vulnerability affects GitLab CE/EE versions 14.3 through 14.3.6, 14.4 through 14.4.4, and 14.5 through 14.5.2.

Mitigation

Upgrade GitLab to a patched version beyond 14.5.2 to resolve the improper input sanitization in emoji HTML rendering.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

1.04%
Probability of exploitation in next 30 days
62.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE