PT-2021-4088 · Gitlab · Gitlab

Yvvdwfon

·

Published

2021-01-05

·

Updated

2024-03-06

·

CVE-2021-22220

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 13.10 and later
Description The issue is related to a stored XSS in the blob viewer of notebooks, which can be exploited by a remote attacker to impact data integrity. This is due to the lack of protection measures for the web page structure.
Recommendations For versions 13.10 and later, update to a version that includes the fix for the stored XSS issue in the blob viewer of notebooks. As a temporary workaround, consider disabling the blob viewer of notebooks until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-04666
BIT-GITLAB-2021-22220
CVE-2021-22220

Affected Products

Gitlab