A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-01T19:26:11.438Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-3265
Updated: 2024-08-03T01:07:05.873Z
Status : Modified
Published: 2022-11-09T23:15:13.187
Modified: 2025-05-01T20:15:32.687
Link: CVE-2022-3265
No data.
OpenCVE Enrichment
No data.
Weaknesses