CVE-2021-22183: XSS
Published Mar 4, 2021
·Updated
An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS in the epics page, which could be exploited with user interactions.
Affected Software
6 affected components
GitLab GitLab>=11.8<13.6.6
GitLab GitLab>=11.8<13.6.6
GitLab GitLab>=13.7.0<13.7.6
GitLab GitLab>=13.7.0<13.7.6
GitLab GitLab>=13.8.0<13.8.2
GitLab GitLab>=13.8.0<13.8.2
Event History
Mar 4, 2021
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22183?
CVE-2021-22183 is considered a moderate severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2021-22183?
To fix CVE-2021-22183, upgrade GitLab to versions 13.6.6 or later, 13.7.6 or later, or 13.8.2 or later.
3
Which versions of GitLab are affected by CVE-2021-22183?
CVE-2021-22183 affects GitLab versions from 11.8 to 13.6.6, as well as specific versions between 13.7.0 and 13.7.6, and between 13.8.0 and 13.8.2.
4
What type of vulnerability is CVE-2021-22183?
CVE-2021-22183 is a stored cross-site scripting (XSS) vulnerability located in the epics page of GitLab.
5
Is user interaction required to exploit CVE-2021-22183?
Yes, exploitation of CVE-2021-22183 requires user interaction.