← Back

CVE-2022-1416

nvd nist
Published: May 19, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

Affected (6)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 1.0.2 to 14.8.6
From 14.9.0 to 14.9.4
From 1.0.2 to 14.8.6
From 14.9.0 to 14.9.4
Version 14.10.0
Version 14.10.0

References (6)

Source: cve@gitlab.com
ExploitIssue TrackingTechnical DescriptionThird Party Advisory
Source: cve@gitlab.com
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory

Timeline

No history available yet.