CVE-2022-2250Open Redirect in Gitlab

CWE-601Open Redirect5 documents5 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 49.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateJul 2

Description

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

NVDgitlab/gitlab11.1.014.0.5+3
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=11.1, <14.10.5, >=15.0, <15.0.4, >=15.1, <15.1.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-qhmc-hgm8-7h94: An open redirect vulnerability in GitLab EE/CE affecting all versions from 112022-07-02
OSV
CVE-2022-2250: An open redirect vulnerability in GitLab EE/CE affecting all versions from 112022-07-01

📋Vendor Advisories

2
GitLab
CVE-2022-2250: An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allo2022-07-01
Debian
CVE-2022-2250: gitlab - An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 ...2022