CVE-2021-22232 log

Source
Severity Low
Remote Yes
Type Content spoofing
Description
HTML injection was possible via the full name field before version 14.0.2 in GitLab CE.
Group Package Affected Fixed Severity Status Ticket
AVG-2125 gitlab 14.0.1-1 14.0.3-1 High Fixed
Date Advisory Group Package Severity Type
06 Jul 2021 ASA-202107-18 AVG-2125 gitlab High multiple issues
References
https://gitlab.com/gitlab-org/gitlab/-/issues/300713
https://hackerone.com/reports/1090634
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22232.json