A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests
2022-10-17T16:15:20.990
2025-05-13T20:15:21.250
Modified
CVSSv3.1: 6.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 15.1.6 | Yes |
| Application | gitlab | gitlab | < 15.1.6 | Yes |
| Application | gitlab | gitlab | < 15.2.4 | Yes |
| Application | gitlab | gitlab | < 15.2.4 | Yes |
| Application | gitlab | gitlab | < 15.3.2 | Yes |
| Application | gitlab | gitlab | < 15.3.2 | Yes |