CVE-2021-22196
02.04.2021, 17:15
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 13.4.0 ≤ 𝑥 < 13.8.7 |
gitlab | gitlab | 13.4.0 ≤ 𝑥 < 13.8.7 |
gitlab | gitlab | 13.9.0 ≤ 𝑥 < 13.9.5 |
gitlab | gitlab | 13.9.0 ≤ 𝑥 < 13.9.5 |
gitlab | gitlab | 13.10.0 ≤ 𝑥 < 13.10.1 |
gitlab | gitlab | 13.10.0 ≤ 𝑥 < 13.10.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References