CVE-2022-1175
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 82.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 82.00% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/353370Broken Link
- https://hackerone.com/reports/1481207Permissions Required, Third Party Advisory
- http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/353370Broken Link
- https://hackerone.com/reports/1481207Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.