CVE-2022-1433

LOW

GitLab 14.4-14.8.5, 14.9-14.9.3, 14.10 - Stored Cross-Site Scripting via Markdown Cache Invalidation Bypass

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1528829

Scores

CVSS v3 2.6
EPSS 0.0014
EPSS Percentile 33.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-79
Status published
Products (2)
gitlab/gitlab 14.10.0 (2 CPE variants)
gitlab/gitlab 14.4.0 - 14.8.6 (2 CPE variants)
Published May 11, 2022
Tracked Since Feb 18, 2026