Related Vulnerabilities: CVE-2021-22232  

HTML injection was possible via the full name field before version 14.0.2 in GitLab CE.

Severity Low

Remote Yes

Type Content spoofing

Description

HTML injection was possible via the full name field before version 14.0.2 in GitLab CE.

AVG-2125 gitlab 14.0.1-1 14.0.3-1 High Fixed

https://gitlab.com/gitlab-org/gitlab/-/issues/300713
https://hackerone.com/reports/1090634
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22232.json