CVE-2022-1416Cross-site Scripting in Gitlab

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 64.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateMay 20

Description

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages5 packages

NVDgitlab/gitlab1.0.214.8.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=1.0.2, <14.8.6, >=14.10.0, <14.10.1, >=14.9.0, <14.9.4+2
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-2h7w-85g4-9cx4: Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 12022-05-20

📋Vendor Advisories

2
GitLab
CVE-2022-1416: Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 142022-05-19
Debian
CVE-2022-1416: gitlab - Missing sanitization of data in Pipeline error messages in GitLab CE/EE affectin...2022