CVE-2022-3573
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.
- CVSS Version 3.1
nvd
CVE ID: CVE-2022-3573
Base Score: 5.4
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3
gitlab
CVE ID: CVE-2022-3573
Base Score: 5.4
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3
Content on GitHub
gmh5225 | watchers:9
CVE-2022-35737
Stranger strings: CVE-2022-35737
Refrence: GitHub
rvermeulen | watchers:1
codeql-cve-2022-35737
A CodeQL query to find CVE 2022-35737
Refrence: GitHub