CVE Vulnerabilities

CVE-2021-22230

Published: Jul 07, 2021 | Modified: Jul 09, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 9.3.0 (including) 13.11.6 (excluding)
Gitlab Gitlab 13.12.0 (including) 13.12.6 (excluding)
Gitlab Gitlab 14.0.0 (including) 14.0.2 (excluding)

References