MEDIUM
CVE-2022-2235
CVSS
5.4
Description
Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
Summary dbcve.org
This is a stored XSS vulnerability in GitLab EE's external issue tracker integration with ZenTao. Due to insufficient input sanitization when processing ZenTao links, attackers can inject malicious JavaScript that executes when victims click on crafted links in the issue tracker.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, or 15.1.1 or later to remediate the insufficient sanitization in the external issue tracker.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.9%
Probability of exploitation in next 30 days
58th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.