Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-39946

Опубликовано: 18 янв. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 8.7

Описание

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

РелизСтатусПримечание
esm-apps/xenial

ignored

not maintainable
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 87%
0.03533
Низкий

3.5 Low

CVSS2

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
больше 3 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVSS3: 8.7
debian
больше 3 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to ...

github
больше 3 лет назад

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

EPSS

Процентиль: 87%
0.03533
Низкий

3.5 Low

CVSS2

8.7 High

CVSS3