Low severity3.5NVD Advisory· Published Jul 6, 2021· Updated Jun 17, 2026
CVE-2021-22232
CVE-2021-22232
Description
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=9.5.0,<13.11.6
- (no CPE)range: <13.11.6, <13.12.6, <14.0.2
- (no CPE)range: >=9.5, <13.11.6
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22232.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/300713nvdBroken Link
- hackerone.com/reports/1090634nvdPermissions Required
News mentions
0No linked articles in our index yet.