VulnerabilityModified
CVE-2022-3381
A crafted URL could be used to redirect users to arbitrary sites
MEDIUM 6.1EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3381.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/376046Broken Link
- https://hackerone.com/reports/1711497Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3381.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/376046Broken Link
- https://hackerone.com/reports/1711497Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.