Related Vulnerabilities: CVE-2021-22223  

A security issue has been found in GitLab before version 14.0.2. Client-Side code injection through Feature Flag name starting with GitLab CE/EE 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

A security issue has been found in GitLab before version 14.0.2. Client-Side code injection through Feature Flag name starting with GitLab CE/EE 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link.

AVG-2125 gitlab 14.0.1-1 Medium Vulnerable

https://about.gitlab.com/releases/2021/07/01/security-release-gitlab-14-0-2-released/#stored-xss-on-audit-log