PT-2021-6755 · Gitlab · Gitlab

Vakzz

·

Published

2021-08-20

·

Updated

2024-03-06

·

CVE-2021-22238

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 13.3 and later
Description The issue is related to a stored XSS vulnerability in GitLab, specifically when using the design feature in issues. This vulnerability allows a remote attacker to impact data integrity by exploiting the lack of protection measures for the web page structure.
Recommendations For GitLab versions 13.3 and later, consider disabling the design feature in issues as a temporary workaround until a patch is available. Restrict access to the design feature to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-02147
BIT-GITLAB-2021-22238
CVE-2021-22238

Affected Products

Gitlab