CVE-2022-3572: XSS
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-3572.
What is the severity of CVE-2022-3572?
The severity of CVE-2022-3572 is critical.
Which versions of GitLab are affected by CVE-2022-3572?
All versions of GitLab from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 are affected by CVE-2022-3572.
How can I exploit this vulnerability?
This vulnerability can be exploited by setting the Jira Connect integration in GitLab to trigger a reflected XSS attack.
Is there a fix available for CVE-2022-3572?
Yes, GitLab has released fixes for this vulnerability in versions 15.3.5 and above, 15.4.4 and above, and 15.5.2 and above.