CVE-2022-1416

MEDIUM

Gitlab < 14.8.6 - XSS

Title source: rule
STIX 2.1

Description

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

References (3)

Core 3
Core References
Exploit, Issue Tracking, Technical Description, Third Party Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/342988
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1362405

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-79
Status published
Products (2)
gitlab/gitlab 14.10.0 (2 CPE variants)
gitlab/gitlab 1.0.2 - 14.8.6 (2 CPE variants)
Published May 19, 2022
Tracked Since Feb 18, 2026