Логотип exploitDog
bind:CVE-2022-3265
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3265

Количество 4

Количество 4

ubuntu логотип

CVE-2022-3265

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2022-3265

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
EPSS: Средний
debian логотип

CVE-2022-3265

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-qxr4-8jqx-8c2w

почти 3 года назад

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
53%
Средний
почти 3 года назад
nvd логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 7.3
53%
Средний
почти 3 года назад
debian логотип
CVE-2022-3265

A cross-site scripting issue has been discovered in GitLab CE/EE affec ...

CVSS3: 7.3
53%
Средний
почти 3 года назад
github логотип
GHSA-qxr4-8jqx-8c2w

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

CVSS3: 5.4
53%
Средний
почти 3 года назад

Уязвимостей на страницу