CVE-2022-3572
Published on: Not Yet Published
Last Modified on: 02/01/2023 05:17:00 PM UTC
Certain versions of Gitlab from Gitlab contain the following vulnerability:
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.
- CVE-2022-3572 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
GitLab - GitLab version >=13.5, <15.4.6
- Affected Vendor/Software:
GitLab - GitLab version >=15.5, <15.5.5
- Affected Vendor/Software:
GitLab - GitLab version >=15.6, <15.6.1
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cross-site scripting in Jira Integration affecting self-hosted instances without strict CSP (#378214) · Issues · GitLab.org / GitLab · GitLab | gitlab.com text/html |
![]() |
HackerOne | hackerone.com text/html |
![]() |
2022/CVE-2022-3572.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
Related QID Numbers
- 690999 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (3cde510a-7135-11ed-a28b-bff032704f00)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | 15.6.0 | All | All | All |
Application | Gitlab | Gitlab | 15.6.0 | All | All | All |
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*:
Discovery Credit
Thanks [ryotak](https://hackerone.com/ryotak) for reporting this vulnerability through our HackerOne bug bounty program
Social Mentions
Source | Title | Posted (UTC) |
---|