A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2022-07-01T15:55:13

Updated: 2024-08-03T00:32:09.532Z

Reserved: 2022-06-27T00:00:00

Link: CVE-2022-2230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-01T16:15:08.227

Modified: 2022-07-13T17:43:23.430

Link: CVE-2022-2230

cve-icon Redhat

No data.