A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.
2022-07-01T16:15:08.227
2024-11-21T07:00:35.153
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 14.10.5 | Yes |
| Application | gitlab | gitlab | < 14.10.5 | Yes |
| Application | gitlab | gitlab | < 15.0.4 | Yes |
| Application | gitlab | gitlab | < 15.0.4 | Yes |
| Application | gitlab | gitlab | 15.1.0 | Yes |
| Application | gitlab | gitlab | 15.1.0 | Yes |