MEDIUM

CVE-2022-3280

Gitlab GitLab 2022-11-09 CVSS v3.1
CVSS
6.1

Description

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

Summary dbcve.org

An open redirect vulnerability in GitLab CE/EE allows attackers to craft malicious URLs that appear to be on a trustworthy GitLab domain but actually redirect users to arbitrary external websites, enabling phishing attacks.

Mitigation

Upgrade GitLab to version 15.3.5, 15.4.4, 15.5.2 or later. Alternatively, implement URL validation to reject redirects to untrusted domains.

Weakness (CWE)

CWE-601 Open Redirect

EPSS Score

0.56%
Probability of exploitation in next 30 days
45.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE