PT-2021-4987 · Datadog+1 · Datadog+2

Shells3Con

·

Published

2021-07-11

·

Updated

2024-03-06

·

CVE-2021-22260

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.7 through 14.0.8 GitLab CE/EE versions 14.1 through 14.1.3 GitLab CE/EE versions 14.2 through 14.2.1
Description The issue is related to a stored Cross-Site Scripting vulnerability in the DataDog integration of GitLab. This vulnerability is associated with insufficient protection of the api keys url web page structure. An attacker can exploit this vulnerability to conduct cross-site scripting attacks, allowing them to execute arbitrary JavaScript code on the victim's behalf.
Recommendations For GitLab CE/EE versions 13.7 through 14.0.8, update to version 14.0.9 or later. For GitLab CE/EE versions 14.1 through 14.1.3, update to version 14.1.4 or later. For GitLab CE/EE versions 14.2 through 14.2.1, update to version 14.2.2 or later. As a temporary workaround, consider restricting access to the DataDog integration until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-05750
BIT-GITLAB-2021-22260
CVE-2021-22260

Affected Products

Datadog
Gitlab
Gitlab Ce/Ee