CVE-2022-2865: XSS
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2865?
CVE-2022-2865 is considered a medium severity cross-site scripting vulnerability.
How do I fix CVE-2022-2865?
To fix CVE-2022-2865, update GitLab to version 15.1.6, 15.2.5 or later, or 15.3.2 or later.
What versions of GitLab are affected by CVE-2022-2865?
CVE-2022-2865 affects all versions of GitLab before 15.1.6, 15.2 from 15.2.0 to 15.2.4, and 15.3 from 15.3.0 to 15.3.1.
Can CVE-2022-2865 lead to a data breach?
Yes, CVE-2022-2865 could potentially allow attackers to execute arbitrary scripts, leading to unauthorized access to sensitive data.
Is CVE-2022-2865 a stored XSS vulnerability?
Yes, CVE-2022-2865 is a stored cross-site scripting vulnerability that can be exploited through the label color settings.