PT-2022-4613 · Gitlab · Gitlab
Yvvdwfon
·
Published
2022-08-30
·
Updated
2025-05-13
·
CVE-2022-2527
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab versions 14.9 through 15.1.5
GitLab versions 15.2 through 15.2.3
GitLab versions 15.3 through 15.3.1
Description
The issue is related to insufficient input validation in GitLab, allowing a remote attacker to inject arbitrary data through the description field in the Incidents Timeline. This could lead to arbitrary requests when a victim interacts with the injected content. An authenticated attacker can exploit this issue.
Recommendations
For GitLab versions 14.9 through 15.1.5, update to version 15.1.6 or later.
For GitLab versions 15.2 through 15.2.3, update to version 15.2.4 or later.
For GitLab versions 15.3 through 15.3.1, update to version 15.3.2 or later.
Exploit
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab