PT-2021-22753 · Gitlab · Gitlab Ce/Ee+1

Saleem Rashid

·

Published

2021-11-04

·

Updated

2024-03-06

·

CVE-2021-39906

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.5 and above
Description The issue arises from improper validation of ipynb files, allowing an attacker to execute arbitrary JavaScript code on the victim's behalf. This enables the attacker to perform actions as the victim, potentially leading to unauthorized access or data manipulation. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For GitLab CE/EE versions 13.5 and above, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the upload and execution of ipynb files until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39906
CVE-2021-39906

Affected Products

Gitlab
Gitlab Ce/Ee