Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-1948

Опубликовано: 28 июл. 2022
Источник: debian
EPSS Низкий

Описание

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabnot-affectedpackage

Примечания

  • https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/

EPSS

Процентиль: 80%
0.0134
Низкий

Связанные уязвимости

CVSS3: 8.7
ubuntu
больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 8.7
nvd
больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVSS3: 5.4
github
больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

EPSS

Процентиль: 80%
0.0134
Низкий