Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/360540 | Broken Link |
https://hackerone.com/reports/1542510 | Permissions Required Third Party Advisory |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2235.json | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-07-01 09:15
Updated : 2022-07-13 10:44
NVD link : CVE-2022-2235
Mitre link : CVE-2022-2235
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
gitlab
- gitlab