PT-2021-6534 · Gitlab · Gitlab

Vovohelo

·

Published

2021-07-07

·

Updated

2024-03-06

·

CVE-2021-22225

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 13.11 and up
Description The issue is related to insufficient input sanitization in markdown, allowing an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown. This can be exploited by a remote attacker to impact data integrity.
Recommendations For GitLab versions 13.11 and up, update to a version that includes the fix for the insufficient input sanitization in markdown to prevent stored cross-site scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-01794
BIT-GITLAB-2021-22225
CVE-2021-22225

Affected Products

Gitlab