CVE-2022-3572
Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.
Related CPE's
References
Vendor Advisory
ExploitVendor Advisory
Permissions RequiredThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics