CVE-2021-22182: XSS
Published Mar 3, 2021
·Updated
An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.
Affected Software
4 affected components
GitLab GitLab>=13.7.0<13.7.6
GitLab GitLab>=13.7.0<13.7.6
GitLab GitLab>=13.8.0<13.8.2
GitLab GitLab>=13.8.0<13.8.2
Event History
Mar 3, 2021
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22182?
CVE-2021-22182 has a medium severity rating due to its potential for stored cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2021-22182?
To fix CVE-2021-22182, upgrade GitLab to version 13.7.7, 13.8.3, or later versions.
3
What impact does CVE-2021-22182 have on GitLab users?
CVE-2021-22182 allows attackers to execute arbitrary JavaScript in the context of the user's browser, potentially compromising confidential data.
4
Which versions of GitLab are affected by CVE-2021-22182?
CVE-2021-22182 affects GitLab versions between 13.7.0 and 13.8.2 inclusive.
5
Is there a workaround for CVE-2021-22182?
There are no known workarounds for CVE-2021-22182 other than upgrading to the patched versions.