CVE-2022-2428: XSS
A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2428?
CVE-2022-2428 has a severity rating of medium due to the potential for attackers to issue arbitrary HTTP requests.
How do I fix CVE-2022-2428?
To fix CVE-2022-2428, upgrade your GitLab instance to version 15.1.6 or later, or to version 15.2.5 or later.
What versions are affected by CVE-2022-2428?
CVE-2022-2428 affects all GitLab versions before 15.1.6, as well as versions between 15.2 to 15.2.4 and 15.3 to 15.3.2.
Is CVE-2022-2428 present in the Community Edition of GitLab?
Yes, CVE-2022-2428 is present in both the Community and Enterprise Editions of GitLab before the specified fixed versions.
What kind of attacks can CVE-2022-2428 facilitate?
CVE-2022-2428 can facilitate attacks where an attacker sends crafted requests through the Jupyter Notebook viewer.