MEDIUM

CVE-2022-4007

Gitlab GitLab 2023-03-08 CVSS v3.1
CVSS
6.1

Description

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

Summary dbcve.org

A stored cross-site scripting (XSS) vulnerability in GitLab CE/EE allows attackers to inject malicious JavaScript into the title field of work items. When victims view these work items, the injected script executes in their browsers, enabling session hijacking, data theft, or performing actions on behalf of authenticated users.

Mitigation

Upgrade GitLab to version 15.7.8, 15.8.4, or 15.9.2 or later to receive the patch that properly sanitizes work item title fields.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.56%
Probability of exploitation in next 30 days
45.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE