MEDIUM
CVE-2022-2250
CVSS
6.1
Description
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.
Summary dbcve.org
Open redirect vulnerability in GitLab EE/CE allows attackers to craft malicious URLs that appear trusted but redirect users to arbitrary external sites. The application fails to properly validate redirect targets before forwarding users.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later to patch the open redirect vulnerability.
Weakness (CWE)
CWE-601
Open Redirect
EPSS Score
1.65%
Probability of exploitation in next 30 days
75.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.