Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3513


An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP.


Published

2023-04-05T20:15:07.350

Last Modified

2025-02-11T17:15:12.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.8.5 Yes
Application gitlab gitlab < 15.8.5 Yes
Application gitlab gitlab < 15.9.4 Yes
Application gitlab gitlab < 15.9.4 Yes
Application gitlab gitlab 15.10.0 Yes
Application gitlab gitlab 15.10.0 Yes

References