CVE-2021-22230: High severity gitlab vulnerability
Published Jul 7, 2021
·Updated
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.
Affected Software
6 affected components
GitLab GitLab>=9.3.0<13.11.6
GitLab GitLab>=13.12.0<13.12.6
GitLab GitLab>=14.0.0<14.0.2
GitLab GitLab>=9.3.0<13.11.6
GitLab GitLab>=13.12.0<13.12.6
GitLab GitLab>=14.0.0<14.0.2
Event History
Jul 7, 2021
CVE Published
via MITRE·10:47 AM
Data Sourced
via MITRE·10:47 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22230?
CVE-2021-22230 has been classified as a high severity vulnerability due to its potential exploitation for submitting malicious code.
2
How do I fix CVE-2021-22230?
To fix CVE-2021-22230, users should upgrade their GitLab installations to versions 13.11.7, 13.12.7, or 14.0.3 or later.
3
Which versions are affected by CVE-2021-22230?
CVE-2021-22230 affects GitLab CE/EE versions from 9.3 to 13.11.6, 13.12.6, and 14.0.2.
4
What type of vulnerability is CVE-2021-22230?
CVE-2021-22230 is categorized as an improper code rendering vulnerability.
5
Can CVE-2021-22230 affect both GitLab CE and EE?
Yes, CVE-2021-22230 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) installations.