CVE-2021-22241: XSS
Published Aug 5, 2021
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.
Affected Software
4 affected components
GitLab GitLab>=14.0.0<14.0.7
GitLab GitLab>=14.0.0<14.0.7
GitLab GitLab>=14.1.0<14.1.2
GitLab GitLab>=14.1.0<14.1.2
Event History
Aug 5, 2021
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22241?
CVE-2021-22241 has a medium severity rating due to its potential to cause stored cross-site scripting vulnerabilities.
2
How do I fix CVE-2021-22241?
To fix CVE-2021-22241, upgrade your GitLab installation to the latest version that is patched against this vulnerability.
3
Which versions are affected by CVE-2021-22241?
CVE-2021-22241 affects all GitLab CE/EE versions starting from 14.0 up to and including 14.1.2.
4
Can CVE-2021-22241 be exploited remotely?
Yes, CVE-2021-22241 can be exploited remotely through the manipulation of default branch names.
5
Is user interaction required to exploit CVE-2021-22241?
User interaction is not required to exploit CVE-2021-22241, making it a more severe risk for vulnerable installations.