PT-2023-13448 · Gitlab · Gitlab Ce/Ee+1

Ryotakon

·

Published

2023-01-12

·

Updated

2025-04-08

·

CVE-2022-3573

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.4 through 15.5.7 GitLab CE/EE versions 15.6 through 15.6.4 GitLab CE/EE versions 15.7 through 15.7.2
Description The issue arises from inadequate filtering of query parameters on the wiki changes page, allowing an attacker to execute arbitrary JavaScript on self-hosted instances without strict Content Security Policy (CSP). This can lead to the execution of arbitrary JavaScript code.
Recommendations For versions 15.4 through 15.5.7, update to version 15.5.7 or later. For versions 15.6 through 15.6.4, update to version 15.6.4 or later. For versions 15.7 through 15.7.2, update to version 15.7.2 or later. As a temporary workaround, consider implementing strict Content Security Policy (CSP) on self-hosted instances to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-3573
CVE-2022-3573

Affected Products

Gitlab
Gitlab Ce/Ee