Description


An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

Related CPE's


a

gitlab

gitlab

6

Weaknesses



CWE-601

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-601

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

4.7 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-09T22:15:14.973Z

3 years ago

Last modified

2025-05-01T18:15:33.323Z

10 months ago