← Back to browse · API

CVE-2022-3265

Severity
HIGH
CVSS
7.3
EPSS
0.86326
Risk score
59.41
CISA KEV
No
PoC
No
Published
2022-11-09
Modified
2025-05-01
First seen
2026-08-07
Aliases
EUVD-2022-42667, GHSA-QXR4-8JQX-8C2W
Products
GitLab:GitLab 15.4, <15.4.4, GitLab:GitLab 15.5, <15.5.2, GitLab:GitLab <15.3.5
Sources
euvd EUVD-2022-42667

Description

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

References