First published: Tue Jan 24 2023(Updated: )
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab GitLab | >=13.5.0<15.4.6 | |
GitLab GitLab | >=13.5.0<15.4.6 | |
GitLab GitLab | >=15.5.0<15.5.5 | |
GitLab GitLab | >=15.5.0<15.5.5 | |
GitLab GitLab | =15.6.0 | |
GitLab GitLab | =15.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-3572.
The severity of CVE-2022-3572 is critical.
All versions of GitLab from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 are affected by CVE-2022-3572.
This vulnerability can be exploited by setting the Jira Connect integration in GitLab to trigger a reflected XSS attack.
Yes, GitLab has released fixes for this vulnerability in versions 15.3.5 and above, 15.4.4 and above, and 15.5.2 and above.