CRITICAL

CVE-2022-3726

Gitlab GitLab 2022-11-10 CVSS v3.1
CVSS
9

Description

Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

Summary dbcve.org

A cross-site request forgery (CSRF) or SSRF vulnerability in GitLab's Swagger/OpenAPI document viewer allows attackers to trick authenticated users into viewing malicious OpenAPI documents that trigger unauthorized HTTP requests to internal services or the GitLab API, performing actions as the victim user.

Mitigation

Upgrade GitLab to version 15.3.5, 15.4.4, or 15.5.2 or later. Until patched, warn users not to open untrusted OpenAPI/Swagger documents in the GitLab UI.

EPSS Score

0.83%
Probability of exploitation in next 30 days
56.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE