CVE-2022-3573: XSS
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3573?
CVE-2022-3573 is an issue discovered in GitLab CE/EE that affects all versions starting from 15.4 before 15.5.7, 15.6 before 15.6.4, and 15.7 before 15.7.2.
What is the severity of CVE-2022-3573?
The severity of CVE-2022-3573 is medium with a CVSS score of 5.4.
How does CVE-2022-3573 affect GitLab CE/EE?
CVE-2022-3573 affects GitLab CE/EE by allowing an attacker to execute arbitrary code due to improper filtering of query parameters in the wiki changes page.
Which versions of GitLab CE/EE are affected by CVE-2022-3573?
All versions starting from 15.4 before 15.5.7, 15.6 before 15.6.4, and 15.7 before 15.7.2 of GitLab CE/EE are affected by CVE-2022-3573.
How can I fix CVE-2022-3573 in GitLab CE/EE?
To fix CVE-2022-3573 in GitLab CE/EE, upgrade to version 15.5.7, 15.6.4, or 15.7.2 or later.