CVE-2022-2904
Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 It was possible to exploit a vulnerability in the external status checks feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
Summary dbcve.org
A stored cross-site scripting (XSS) vulnerability exists in GitLab's external status checks feature across versions 15.2.x (before 15.2.5), 15.3.x (before 15.3.4), and 15.4.x (before 15.4.1). Attackers can inject malicious scripts that execute in victim browsers, enabling unauthorized actions to be performed on behalf of authenticated users.
Mitigation
Upgrade GitLab to version 15.4.1 or later (or to 15.3.4/15.2.5 for respective branches) to apply the security patch. Review external status checks configurations for any malicious payloads that may have been injected.