PT-2021-6694 · Gitlab · Gitlab Ce/Ee+1

Joaxcar

·

Published

2021-07-10

·

Updated

2024-03-06

·

CVE-2021-22241

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 14.0 and later
Description The issue is related to a stored cross-site-scripting vulnerability in GitLab CE/EE, which can be exploited via a specifically crafted default branch name. This allows a remote attacker to impact data integrity due to the lack of filtering of the default branch name field.
Recommendations For versions 14.0 and later, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting the ability to set default branch names to trusted users until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02049
BIT-GITLAB-2021-22241
CVE-2021-22241

Affected Products

Gitlab
Gitlab Ce/Ee