Rapid7

vulnerability

FreeBSD: VID-66d1c277-652a-11eb-bb3f-001b217b3468 (CVE-2021-22169): Gitlab -- Multiple vulnerabilities

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Feb 2, 2021
Added
Feb 3, 2021
Modified
Mar 25, 2026

Description

Gitlab reports: Stored XSS in merge request Stored XSS in epic's pages Sensitive GraphQL variables exposed in structured log Guest user can see tag names in private projects Information disclosure via error message DNS rebinding protection bypass Validate existence of private project

Solution

freebsd-upgrade-package-gitlab-ce
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.