CVE-2022-3486Open Redirect in Gitlab

CWE-601Open Redirect5 documents5 sources
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateNov 10

Description

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

NVDgitlab/gitlab9.4.015.3.5+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=15.4, <15.4.4, >=15.5, <15.5.2, >=9.4, <15.3.5+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-m9gh-48vw-5j3h: An open redirect vulnerability in GitLab EE/CE affecting all versions from 92022-11-10
OSV
CVE-2022-3486: An open redirect vulnerability in GitLab EE/CE affecting all versions from 92022-11-09

📋Vendor Advisories

2
GitLab
CVE-2022-3486: An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows2022-11-09
Debian
CVE-2022-3486: gitlab - An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 p...2022