DOM-based cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - #VU54572

 

DOM-based cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - #VU54572

Published: July 6, 2021


Vulnerability identifier: #VU54572
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when processing clipboard contents. A remote attacker can trick the victim to copy specially crafted contents and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

Remediation

Install updates from vendor's website.

GitLab Enterprise Edition - addressed in versions 13.11.6, 13.12.6, 14.0.2
Gitlab Community Edition - addressed in versions 13.11.6, 13.12.6, 14.0.2

External References

Related Security Bulletins