CVE-2021-22234: XSS
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22234?
CVE-2021-22234 is classified as a critical vulnerability due to its ability to allow attackers to read arbitrary files on the server.
How do I fix CVE-2021-22234?
To remediate CVE-2021-22234, update GitLab to version 13.11.7, 13.12.8, or 14.0.4 or later.
Which versions of GitLab are affected by CVE-2021-22234?
CVE-2021-22234 affects GitLab versions from 13.11.0 to 13.11.6, from 13.12.0 to 13.12.7, and from 14.0.0 to 14.0.3.
What are the potential impacts of exploiting CVE-2021-22234?
Exploiting CVE-2021-22234 could lead to unauthorized access to sensitive files on the server.
Is CVE-2021-22234 specific to GitLab CE or EE?
CVE-2021-22234 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) across specified vulnerable versions.