CVE-2022-3265
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 86.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 86.33% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3265.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/374976Broken Link
- https://hackerone.com/reports/1693150Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3265.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/374976Broken Link
- https://hackerone.com/reports/1693150Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.