CVE-2021-22234

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/08/2021
Last modified:
22/07/2022

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 13.11.0 (including) 13.11.7 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.11.0 (including) 13.11.7 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 13.12.0 (including) 13.12.8 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.12.0 (including) 13.12.8 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.0.0 (including) 14.0.4 (including)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.0.0 (including) 14.0.4 (including)