CVE-2022-4007
Last modified
CVE-2022-4007 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 15.3, < 15.7.8 |
| Gitlab | Gitlab | >= 15.8.0, < 15.8.4 |
| Gitlab | Gitlab | >= 15.9.0, < 15.9.2 |
References
- https://hackerone.com/reports/1767745Broken Link, Permissions Required
- https://hackerone.com/reports/1767745Broken Link, Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4007?
How severe is CVE-2022-4007?
How do I fix CVE-2022-4007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40050ZFile v4.1.1 was discovered to contain an arbitrary file upl…9.8
- CVE-2022-40055An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL …9.8
- CVE-2022-4006A vulnerability, which was classified as problematic, has be…7.5
- CVE-2022-40067Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
- CVE-2022-40068Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via…7.5
- CVE-2022-40069]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow v…7.5
- CVE-2022-40070Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
- CVE-2022-40071Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
- CVE-2022-40072Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
- CVE-2022-40073Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
- CVE-2022-40074Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
- CVE-2022-40075Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow vi…7.5
Are you affected by CVE-2022-4007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
