CVE-2022-4007
Description
A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.
Summary dbcve.org
A stored cross-site scripting (XSS) vulnerability in GitLab CE/EE allows attackers to inject malicious JavaScript into the title field of work items. When victims view these work items, the injected script executes in their browsers, enabling session hijacking, data theft, or performing actions on behalf of authenticated users.
Mitigation
Upgrade GitLab to version 15.7.8, 15.8.4, or 15.9.2 or later to receive the patch that properly sanitizes work item title fields.