CVE-2021-39946
18.01.2022, 17:15
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 14.3 ≤ 𝑥 < 14.3.6 |
gitlab | gitlab | 14.3 ≤ 𝑥 < 14.3.6 |
gitlab | gitlab | 14.4 ≤ 𝑥 < 14.4.4 |
gitlab | gitlab | 14.4 ≤ 𝑥 < 14.4.4 |
gitlab | gitlab | 14.5 ≤ 𝑥 < 14.5.2 |
gitlab | gitlab | 14.5 ≤ 𝑥 < 14.5.2 |
𝑥
= Vulnerable software versions
References