CVE-2022-1433: XSS
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1433?
CVE-2022-1433 has been rated as a high severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2022-1433?
To fix CVE-2022-1433, upgrade GitLab to version 14.8.6 or later, 14.9.4 or later, or 14.10.1 or later.
Which versions are affected by CVE-2022-1433?
CVE-2022-1433 affects GitLab versions starting from 14.4 before 14.8.6, 14.9 before 14.9.4, and 14.10 before 14.10.1.
What kind of vulnerability is CVE-2022-1433?
CVE-2022-1433 is a vulnerability related to inadequate invalidation of Markdown caching, which may lead to XSS attacks.
Can CVE-2022-1433 be exploited remotely?
Yes, CVE-2022-1433 can potentially be exploited remotely if the affected version of GitLab is accessible.