CVE-2021-22238
medium · 6.8An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.
6.8
CVSS
71.8%
EPSS (exploit prob.)
99th
EPSS percentile
2021-08-20
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gitlab | gitlab | >= 13.3.0, < 13.12.9 |
| gitlab | gitlab | >= 13.3.0, < 13.12.9 |
| gitlab | gitlab | >= 14.0.0, < 14.0.7 |
| gitlab | gitlab | >= 14.0.0, < 14.0.7 |
| gitlab | gitlab | >= 14.1.0, < 14.1.2 |
| gitlab | gitlab | >= 14.1.0, < 14.1.2 |
Check a specific version with /api/v1/cve/match.
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22238.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/332420
- https://hackerone.com/reports/1212067
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22238.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/332420
- https://hackerone.com/reports/1212067
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-22238