First published: Fri Jul 01 2022(Updated: )
An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=11.1.0<14.0.5 | |
GitLab | >=11.1.0<14.10.5 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | =15.1.0 | |
GitLab | =15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2250 is classified as a medium severity vulnerability due to its potential to mislead users through open redirects.
To fix CVE-2022-2250, update your GitLab installation to version 14.10.5, 15.0.4, or 15.1.1 or later.
CVE-2022-2250 affects GitLab EE/CE versions from 11.1.0 to prior 14.10.5, 15.0.0 to prior 15.0.4, and 15.1.0 to prior 15.1.1.
CVE-2022-2250 is an open redirect vulnerability that allows attackers to redirect users to arbitrary URLs.
Yes, CVE-2022-2250 could potentially be exploited in phishing attacks by tricking users into visiting malicious sites.