VulnerabilityModified
CVE-2022-3288
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
MEDIUM 4.3EPSS 0.69%
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-471
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3288.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/354948Broken Link, Vendor Advisory
- https://hackerone.com/reports/1498354Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3288.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/354948Broken Link, Vendor Advisory
- https://hackerone.com/reports/1498354Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/354948Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.