PT-2022-13886 · Gitlab · Gitlab

Published

2022-05-11

·

Updated

2024-03-06

·

CVE-2022-1433

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 14.4 through 14.8.5 GitLab versions 14.9 through 14.9.3 GitLab versions 14.10 through 14.10.0
Description An issue has been discovered in GitLab where missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS to persist and execute.
Recommendations For GitLab versions 14.4 through 14.8.5, update to version 14.8.6 or later. For GitLab versions 14.9 through 14.9.3, update to version 14.9.4 or later. For GitLab versions 14.10 through 14.10.0, update to version 14.10.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-1433
CVE-2022-1433

Affected Products

Gitlab