CVE-2021-39946
EUVD-2021-2630218.01.2022, 17:15
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 14.3 ≤ 𝑥 < 14.3.6 |
| gitlab | gitlab | 14.3 ≤ 𝑥 < 14.3.6 |
| gitlab | gitlab | 14.4 ≤ 𝑥 < 14.4.4 |
| gitlab | gitlab | 14.4 ≤ 𝑥 < 14.4.4 |
| gitlab | gitlab | 14.5 ≤ 𝑥 < 14.5.2 |
| gitlab | gitlab | 14.5 ≤ 𝑥 < 14.5.2 |
𝑥
= Vulnerable software versions
References