MEDIUM
CVE-2022-3486
CVSS
6.1
Description
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.
Summary dbcve.org
An open redirect vulnerability in GitLab EE/CE allows attackers to craft malicious URLs that appear to originate from a trusted GitLab instance but redirect users to arbitrary external websites. This could facilitate phishing attacks by exploiting user trust in legitimate GitLab URLs.
Mitigation
Upgrade GitLab to version 15.3.5, 15.4.4, or 15.5.2 or later. Alternatively, implement URL validation to reject redirect destinations that do not point to trusted domains.
Weakness (CWE)
CWE-601
Open Redirect
EPSS Score
0.78%
Probability of exploitation in next 30 days
54.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.