CVE-2022-2230
01.07.2022, 16:15
A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 14.4.0 ≤ 𝑥 < 14.10.5 |
gitlab | gitlab | 14.4.0 ≤ 𝑥 < 14.10.5 |
gitlab | gitlab | 15.0.0 ≤ 𝑥 < 15.0.4 |
gitlab | gitlab | 15.0.0 ≤ 𝑥 < 15.0.4 |
gitlab | gitlab | 15.1.0 |
gitlab | gitlab | 15.1.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References