MEDIUM
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1
Published Jan 18, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.97%
Description
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.
Affected products
-
- Version <14.4.5StatusaffectedConstraints-
- Version >=14.5.0, <14.5.3StatusaffectedConstraints-
- Version >=14.6.0, <14.6.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15337 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0124.json x_refsource_CONFIRMThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/340176 x_refsource_MISCBroken Link
- https://hackerone.com/reports/1310778 x_refsource_MISCPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15337 | Advisory | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0124.json | x_refsource_CONFIRMThird Party Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/340176 | x_refsource_MISCBroken Link | |
| https://hackerone.com/reports/1310778 | x_refsource_MISCPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jan 18, 2022
Updated Aug 2, 2024
Reserved Jan 5, 2022
Link CVE-2022-0124
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-15337 Assigner GitLab
Published Jan 18, 2022
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2022-15337