QID 379221
QID 379221: GitLab EE Cross-Site Scripting (XSS) Vulnerability (CVE-2022-4092)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2022-4092: An issue has been discovered in GitLab EE that it is possible to create a malicious README page due to improper neutralisation of user supplied input.
Affected Versions:
GitLab EE version 15.6.0
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability attacker can create a malicious README page due to improper neutralisation of user supplied input.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
- GitLab Security Advisory -
about.gitlab.com/releases/2022/11/30/security-release-gitlab-15-6-1-released/
CVEs related to QID 379221
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Releases |
|