MEDIUM
CVE-2022-3381
CVSS
6.1
Description
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
Summary dbcve.org
GitLab versions 10.0 through 15.7.8, 15.8.x before 15.8.4, and 15.9.x before 15.9.2 contain an open redirect vulnerability where crafted URLs can redirect authenticated or unauthenticated users to arbitrary external websites, potentially enabling phishing attacks.
Mitigation
Update GitLab to version 15.7.9, 15.8.4, 15.9.2 or later to patch the open redirect vulnerability.
Weakness (CWE)
CWE-601
Open Redirect
EPSS Score
0.61%
Probability of exploitation in next 30 days
47.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.