First published: Wed Mar 03 2021(Updated: )
An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS in merge request.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.7.0<13.7.6 | |
GitLab | >=13.7.0<13.7.6 | |
GitLab | >=13.8.0<13.8.2 | |
GitLab | >=13.8.0<13.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22182 has a medium severity rating due to its potential for stored cross-site scripting (XSS) vulnerabilities.
To fix CVE-2021-22182, upgrade GitLab to version 13.7.7, 13.8.3, or later versions.
CVE-2021-22182 allows attackers to execute arbitrary JavaScript in the context of the user's browser, potentially compromising confidential data.
CVE-2021-22182 affects GitLab versions between 13.7.0 and 13.8.2 inclusive.
There are no known workarounds for CVE-2021-22182 other than upgrading to the patched versions.