MEDIUM

CVE-2022-0283

Gitlab GitLab 2022-03-28 CVSS v3.1
CVSS
6.1

Description

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.

Summary dbcve.org

Open redirect vulnerability in GitLab's Jira integration allows attackers to craft malicious URLs that cause the application to redirect users to attacker-controlled websites, potentially facilitating phishing attacks or credential theft.

Mitigation

Upgrade GitLab to version 13.5 or later to patch the open redirect vulnerability in the Jira integration feature.

Weakness (CWE)

CWE-601 Open Redirect

EPSS Score

0.77%
Probability of exploitation in next 30 days
54.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE