MEDIUM

CVE-2022-2904

Gitlab GitLab 2022-11-02 CVSS v3.1
CVSS
5.4

Description

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability exists in GitLab's external status checks feature across versions 15.2.x (before 15.2.5), 15.3.x (before 15.3.4), and 15.4.x (before 15.4.1). Attackers can inject malicious scripts that execute in victim browsers, enabling unauthorized actions to be performed on behalf of authenticated users.

Mitigation

Upgrade GitLab to version 15.4.1 or later (or to 15.3.4/15.2.5 for respective branches) to apply the security patch. Review external status checks configurations for any malicious payloads that may have been injected.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE