PT-2021-4987 · Datadog+1 · Datadog+2
Shells3Con
·
Published
2021-07-11
·
Updated
2024-03-06
·
CVE-2021-22260
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 13.7 through 14.0.8
GitLab CE/EE versions 14.1 through 14.1.3
GitLab CE/EE versions 14.2 through 14.2.1
Description
The issue is related to a stored Cross-Site Scripting vulnerability in the DataDog integration of GitLab. This vulnerability is associated with insufficient protection of the
api keys url web page structure. An attacker can exploit this vulnerability to conduct cross-site scripting attacks, allowing them to execute arbitrary JavaScript code on the victim's behalf.Recommendations
For GitLab CE/EE versions 13.7 through 14.0.8, update to version 14.0.9 or later.
For GitLab CE/EE versions 14.1 through 14.1.3, update to version 14.1.4 or later.
For GitLab CE/EE versions 14.2 through 14.2.1, update to version 14.2.2 or later.
As a temporary workaround, consider restricting access to the DataDog integration until a patch is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datadog
Gitlab
Gitlab Ce/Ee