CVE-2022-3265: XSS
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3265?
CVE-2022-3265 has a high severity due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-3265?
To fix CVE-2022-3265, update your GitLab installation to version 15.3.5, 15.4.4 or 15.5.2 or later.
What versions of GitLab are affected by CVE-2022-3265?
CVE-2022-3265 affects all GitLab CE/EE versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
What type of vulnerability is CVE-2022-3265?
CVE-2022-3265 is a cross-site scripting (XSS) vulnerability that allows attackers to potentially execute arbitrary scripts.
Is user data at risk due to CVE-2022-3265?
Yes, CVE-2022-3265 poses a risk to user data as it allows attackers to perform actions on behalf of users through stored XSS.