CVE-2022-1175
high · 8.7Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
8.7
CVSS
82.0%
EPSS (exploit prob.)
100th
EPSS percentile
2022-04-04
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gitlab | gitlab | >= 14.4.0, < 14.7.7 |
| gitlab | gitlab | >= 14.4.0, < 14.7.7 |
| gitlab | gitlab | >= 14.8.0, < 14.8.5 |
| gitlab | gitlab | >= 14.8.0, < 14.8.5 |
| gitlab | gitlab | >= 14.9.0, < 14.9.2 |
| gitlab | gitlab | >= 14.9.0, < 14.9.2 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/353370
- https://hackerone.com/reports/1481207
- http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/353370
- https://hackerone.com/reports/1481207
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-1175