CVE-2022-3486: Medium severity gitlab vulnerability
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3486?
The severity of CVE-2022-3486 is considered high due to the potential for exploitation via open redirects.
How do I fix CVE-2022-3486?
To fix CVE-2022-3486, update your GitLab instance to version 15.3.5, 15.4.4, or 15.5.2 or later.
What versions of GitLab are affected by CVE-2022-3486?
CVE-2022-3486 affects all GitLab EE/CE versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
What are the potential impacts of CVE-2022-3486?
The potential impacts of CVE-2022-3486 include enabling attackers to redirect users to malicious sites through trusted URLs.
Is CVE-2022-3486 exploitable without authentication?
Yes, CVE-2022-3486 can be exploited without user authentication, making it particularly concerning.