CVE-2021-39946
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
18/01/2022
Last modified:
25/01/2022
Description
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.3 (including) | 14.3.6 (excluding) |
| cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.3 (including) | 14.3.6 (excluding) |
| cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.4 (including) | 14.4.4 (excluding) |
| cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.4 (including) | 14.4.4 (excluding) |
| cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.5 (including) | 14.5.2 (excluding) |
| cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.5 (including) | 14.5.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



