CVE-2021-39910

LOW

GitLab 12.6-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - HTML Injection via Swagger UI

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1133656

Scores

CVSS v3 2.6
EPSS 0.0018
EPSS Percentile 39.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 12.6.0 - 14.3.6 (2 CPE variants)
Published Dec 13, 2021
Tracked Since Feb 18, 2026