PT-2021-22756 · Gitlab · Gitlab Ce/Ee+1

Published

2021-12-13

·

Updated

2024-03-06

·

CVE-2021-39910

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.6 through 14.3.6 GitLab CE/EE versions 14.4 through 14.4.4 GitLab CE/EE versions 14.5 through 14.5.2
Description An issue has been discovered in GitLab CE/EE, where it was vulnerable to HTML Injection through the Swagger UI feature.
Recommendations For versions 12.6 through 14.3.6, update to version 14.3.6 or later. For versions 14.4 through 14.4.4, update to version 14.4.4 or later. For versions 14.5 through 14.5.2, update to version 14.5.2 or later. As a temporary workaround, consider disabling the Swagger UI feature until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39910
CVE-2021-39910

Affected Products

Gitlab
Gitlab Ce/Ee