Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-02T23:55:24.361Z
Reserved: 2022-03-30T00:00:00
Link: CVE-2022-1175

No data.

Status : Modified
Published: 2022-04-04T20:15:10.040
Modified: 2024-11-21T06:40:11.400
Link: CVE-2022-1175

No data.

No data.