MEDIUM
CVE-2022-2500
CVSS
5.4
Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.
Summary dbcve.org
A stored XSS vulnerability in GitLab CI/CD job error messages allows attackers to inject malicious JavaScript that executes when other users view these messages, enabling session hijacking and actions on behalf of victims.
Mitigation
Upgrade GitLab to version 15.0.5 or later, 15.1.4 or later, or 15.2.1 or later to resolve the XSS in job error messages.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.72%
Probability of exploitation in next 30 days
52.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.