CRITICAL
CVE-2022-3726
CVSS
9
Description
Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.
Summary dbcve.org
A cross-site request forgery (CSRF) or SSRF vulnerability in GitLab's Swagger/OpenAPI document viewer allows attackers to trick authenticated users into viewing malicious OpenAPI documents that trigger unauthorized HTTP requests to internal services or the GitLab API, performing actions as the victim user.
Mitigation
Upgrade GitLab to version 15.3.5, 15.4.4, or 15.5.2 or later. Until patched, warn users not to open untrusted OpenAPI/Swagger documents in the GitLab UI.
EPSS Score
0.83%
Probability of exploitation in next 30 days
56.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.