CVE-2021-39906Cross-site Scripting in Gitlab

Severity
6.1MEDIUMNVD
EPSS
1.2%
top 21.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5
Latest updateMay 24

Description

Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

NVDgitlab/gitlab13.5.014.2.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=13.5, <14.2.6, >=14.3, <14.3.4, >=14.4, <14.4.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-6cxq-rcp9-rqr8: Improper validation of ipynb files in GitLab CE/EE version 132022-05-24
OSV
CVE-2021-39906: Improper validation of ipynb files in GitLab CE/EE version 132021-11-05

📋Vendor Advisories

2
GitLab
CVE-2021-39906: Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's beha2021-11-05
Debian
CVE-2021-39906: gitlab - Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows...2021