CVE

CVE-2021-39885

CVE-2021-39885

A Stored XSS in merge request creation page in Gitlab EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim’s behalf via malicious approval rule names

Source: CVE-2021-39885

Exit mobile version