← All CVEs

CVE-2022-1175

high · 8.7

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

8.7
CVSS
82.0%
EPSS (exploit prob.)
100th
EPSS percentile
2022-04-04
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
gitlabgitlab>= 14.4.0, < 14.7.7
gitlabgitlab>= 14.4.0, < 14.7.7
gitlabgitlab>= 14.8.0, < 14.8.5
gitlabgitlab>= 14.8.0, < 14.8.5
gitlabgitlab>= 14.9.0, < 14.9.2
gitlabgitlab>= 14.9.0, < 14.9.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-1175