CVE-2021-22232: Path Traversal
Published Jul 6, 2021
·Updated
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
Affected Software
3 affected components
GitLab GitLab>=9.5.0<13.11.6
GitLab GitLab>=13.12.0<13.12.6
GitLab GitLab>=14.0.0<14.0.2
Event History
Jul 6, 2021
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22232?
CVE-2021-22232 is classified as a medium severity vulnerability due to its potential for HTML injection attacks.
2
How do I fix CVE-2021-22232?
To fix CVE-2021-22232, update your GitLab installation to version 13.11.6, 13.12.6, or 14.0.2 or later.
3
What versions are affected by CVE-2021-22232?
CVE-2021-22232 affects GitLab versions prior to 13.11.6, 13.12.6, and 14.0.2.
4
Can CVE-2021-22232 be exploited remotely?
Yes, CVE-2021-22232 can be exploited remotely by an attacker through the full name field.
5
What impact does CVE-2021-22232 have on users?
The impact of CVE-2021-22232 allows unauthorized HTML content to be injected, potentially compromising user data.