CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.4. It affects GitLab.
CVE
CVE-2022-2500
Severity
MEDIUM
CVSS
4.4
EPSS
0.71%
GitLab
Original NVD Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.
Related CVEs
Other vulnerabilities affecting the same vendor(s)