QID 375400
Date Published: 2021-03-24
QID 375400: Gitlab Cross-Site Scripting Vulnerability (gitlab-13-9-2)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
CVE-2021-22185 - Insufficient input sanitization in wikis in GitLab allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted commit to a wiki.
Affected Versions:
GitLab Community Edition (CE) and Enterprise Edition (EE):
GitLab CE/EE version 13.8 and up, and prior to patch versions 13.9.2, 13.8.5 and 13.7.8
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation could allow cross-site scripting on the server.
Solution
The vendor has released patch, For more information please visit gitlab-13-9-2
Vendor References
- security-release-gitlab-13-9-2-released -
about.gitlab.com/releases/2021/03/04/security-release-gitlab-13-9-2-released/
CVEs related to QID 375400
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| gitlab-13-9-2 |
|