PT-2023-13448 · Gitlab · Gitlab Ce/Ee+1

Ryotakon

·

Publicado

2023-01-12

·

Atualizado

2025-04-08

·

CVE-2022-3573

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.4 through 15.5.7 GitLab CE/EE versions 15.6 through 15.6.4 GitLab CE/EE versions 15.7 through 15.7.2
Description The issue arises from inadequate filtering of query parameters on the wiki changes page, allowing an attacker to execute arbitrary JavaScript on self-hosted instances without strict Content Security Policy (CSP). This can lead to the execution of arbitrary JavaScript code.
Recommendations For versions 15.4 through 15.5.7, update to version 15.5.7 or later. For versions 15.6 through 15.6.4, update to version 15.6.4 or later. For versions 15.7 through 15.7.2, update to version 15.7.2 or later. As a temporary workaround, consider implementing strict Content Security Policy (CSP) on self-hosted instances to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-GITLAB-2022-3573
CVE-2022-3573

Produtos afetados

Gitlab
Gitlab Ce/Ee