CVE-2022-3280: Medium severity gitlab vulnerability
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3280?
CVE-2022-3280 has been rated as a medium severity vulnerability due to its potential for open redirection attacks.
How do I fix CVE-2022-3280?
To mitigate CVE-2022-3280, upgrade GitLab to versions 15.3.5, 15.4.4, or 15.5.2 or later.
What are the affected versions in CVE-2022-3280?
CVE-2022-3280 affects all versions of GitLab from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
What type of attack does CVE-2022-3280 facilitate?
CVE-2022-3280 allows attackers to execute open redirect attacks, tricking users into visiting malicious URLs.
Is CVE-2022-3280 applicable to both GitLab CE and EE?
Yes, CVE-2022-3280 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) across the specified versions.