{"api_version":"1","generated_at":"2026-07-23T14:32:41+00:00","cve":"CVE-2021-22260","urls":{"html":"https://cve.report/CVE-2021-22260","api":"https://cve.report/api/cve/CVE-2021-22260.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-22260","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-22260"},"summary":{"title":"CVE-2021-22260","description":"A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2021-11-05 00:15:00","updated_at":"2022-09-30 02:33:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://hackerone.com/reports/1257383","name":"https://hackerone.com/reports/1257383","refsource":"MISC","tags":[],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336614","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/336614","refsource":"MISC","tags":[],"title":"Stored XSS in DataDog Integration affects maintainers/owners (#336614) · Issues · GitLab.org / GitLab · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json","refsource":"CONFIRM","tags":[],"title":"2021/CVE-2021-22260.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-22260","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22260","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks shells3c for reporting this vulnerability through our HackerOne bug bounty program","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"22260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"22260","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-22260","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=13.7, <14.0.9"},{"version_value":">=14.1, <14.1.4"},{"version_value":">=14.2, <14.2.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper neutralization of input during web page generation ('cross-site scripting') in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/336614","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/336614","refsource":"MISC"},{"name":"https://hackerone.com/reports/1257383","url":"https://hackerone.com/reports/1257383","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22260.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf"}]},"impact":{"cvss":{"vectorString":"AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","version":"3.1","baseScore":7.6,"baseSeverity":"HIGH"}},"credit":[{"lang":"eng","value":"Thanks shells3c for reporting this vulnerability through our HackerOne bug bounty program"}]},"nvd":{"publishedDate":"2021-11-05 00:15:00","lastModifiedDate":"2022-09-30 02:33:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.2.0","versionEndExcluding":"14.2.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.0.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.7.0","versionEndExcluding":"14.0.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"22260","Ordinal":"196961","Title":"CVE-2021-22260","CVE":"CVE-2021-22260","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"22260","Ordinal":"1","NoteData":"A stored Cross-Site Scripting vulnerability in the DataDog integration in GitLab CE/EE version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf","Type":"Description","Title":null},{"CveYear":"2021","CveId":"22260","Ordinal":"2","NoteData":"2021-11-04","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"22260","Ordinal":"3","NoteData":"2021-11-04","Type":"Other","Title":"Modified"}]}}}