CVE-2021-22185: XSS
Published Mar 24, 2021
·Updated
Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki
Affected Software
4 affected components
GitLab GitLab>=13.8.0<13.8.5
GitLab GitLab>=13.8.0<13.8.5
GitLab GitLab>=13.9.0<13.9.2
GitLab GitLab>=13.9.0<13.9.2
Event History
Mar 24, 2021
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22185?
CVE-2021-22185 has a high severity rating due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2021-22185?
To fix CVE-2021-22185, upgrade your GitLab installation to version 13.8.5 or later, or 13.9.2 or later.
3
What software is affected by CVE-2021-22185?
CVE-2021-22185 affects GitLab versions 13.8.0 through 13.8.5 and 13.9.0 through 13.9.2 for both community and enterprise editions.
4
What kind of attack does CVE-2021-22185 facilitate?
CVE-2021-22185 allows an attacker to conduct stored cross-site scripting attacks via specially crafted wiki commits.
5
Is CVE-2021-22185 specific to certain GitLab features?
Yes, CVE-2021-22185 specifically affects the wiki feature in GitLab.