← Back to browse · API

CVE-2022-2230

Severity
HIGH
CVSS
8.1
EPSS
0.56469
Risk score
52.16
CISA KEV
No
PoC
No
Published
2022-07-01
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-34510, GHSA-Q874-XRMJ-FH8Q
Products
GitLab:GitLab 14.4, <14.10.5, GitLab:GitLab 15.0, <15.0.4, GitLab:GitLab 15.1, <15.1.1
Sources
euvd EUVD-2022-34510

Description

A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

References