Medium severity4.9NVD Advisory· Published Jul 7, 2021· Updated Jun 17, 2026
CVE-2021-22230
CVE-2021-22230
Description
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=9.3.0,<13.11.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=9.3.0,<13.11.6
- (no CPE)range: 9.3 <= 13.11.6, 13.12.6, 14.0.2
- (no CPE)range: >=9.3, <13.11.6
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22230.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/211976nvdBroken Link
News mentions
0No linked articles in our index yet.