Skip to main content

CVE-2022-3573

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.

nvd
CVE ID: CVE-2022-3573
Base Score: 5.4
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3
gitlab
CVE ID: CVE-2022-3573
Base Score: 5.4
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3

Content on GitHub

gmh5225 | watchers:9

CVE-2022-35737
Stranger strings: CVE-2022-35737

Refrence: GitHub

rvermeulen | watchers:1

codeql-cve-2022-35737
A CodeQL query to find CVE 2022-35737

Refrence: GitHub

Refrence: NVDMITRE