CVE-2021-22199: XSS
Published Apr 22, 2021
·Updated
An issue has been discovered in GitLab affecting all versions starting with 12.9. GitLab was vulnerable to a stored XSS if scoped labels were used.
Affected Software
6 affected components
GitLab GitLab>=12.9<13.8.7
GitLab GitLab>=12.9<13.8.7
GitLab GitLab>=13.9.0<13.9.5
GitLab GitLab>=13.9.0<13.9.5
GitLab GitLab>=13.10.0<13.10.1
GitLab GitLab>=13.10.0<13.10.1
Event History
Apr 22, 2021
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22199?
The severity of CVE-2021-22199 is considered high due to its potential for stored XSS attacks.
2
How do I fix CVE-2021-22199?
To fix CVE-2021-22199, upgrade your GitLab instance to version 13.8.8 or later.
3
Which versions of GitLab are affected by CVE-2021-22199?
All GitLab versions starting from 12.9 up to 13.8.7, as well as 13.9.0 to 13.9.5, and 13.10.0 to 13.10.1 are affected by CVE-2021-22199.
4
What type of vulnerability is CVE-2021-22199?
CVE-2021-22199 is a stored cross-site scripting (XSS) vulnerability.
5
Is user interaction required to exploit CVE-2021-22199?
Yes, user interaction is required to exploit CVE-2021-22199, specifically through the use of scoped labels.