Gitlab · Gitlab Ce/Ee · CVE-2021-39946
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 14.3 through 14.3.6
GitLab CE/EE versions 14.4 through 14.4.4
GitLab CE/EE versions 14.5 through 14.5.2
**Description**
The issue is related to the improper neutralization of user input, allowing an attacker to exploit XSS by abusing the generation of HTML code related to emojis.
**Recommendations**
For versions 14.3 through 14.3.6, update to a version outside of this range to resolve the issue.
For versions 14.4 through 14.4.4, update to a version outside of this range to resolve the issue.
For versions 14.5 through 14.5.2, update to a version outside of this range to resolve the issue.