CVE-2022-4007

MEDIUM

GitLab 15.3-15.7.8, 15.8-15.8.4, 15.9-15.9.2 - Stored Cross-Site Scripting in Work Item Title Field

Title source: llm
STIX 2.1

Description

A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.

Scores

CVSS v3 5.4
EPSS 0.0105
EPSS Percentile 77.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 15.3 - 15.7.8 (2 CPE variants)
Published Mar 08, 2023
Tracked Since Feb 18, 2026