CVE-2021-22225: XSS
Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22225?
CVE-2021-22225 has a medium severity rating due to its potential impact on user data through stored cross-site scripting.
How do I fix CVE-2021-22225?
To remediate CVE-2021-22225, upgrade GitLab to a version that is not affected, such as 13.11.6, 13.12.6, or 14.0.3 and later.
What type of vulnerability is CVE-2021-22225?
CVE-2021-22225 is a stored cross-site scripting (XSS) vulnerability caused by insufficient input sanitization in markdown processing.
What versions of GitLab are affected by CVE-2021-22225?
GitLab versions 13.11.3 to 13.11.6, 13.12.0 to 13.12.6, and 14.0.0 to 14.0.2 are affected by CVE-2021-22225.
Is CVE-2021-22225 exploitable remotely?
Yes, CVE-2021-22225 can be exploited remotely through crafted markdown submissions that lead to stored XSS attacks.