A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2022-10-17T00:00:00

Updated: 2024-08-03T01:07:05.881Z

Reserved: 2022-09-23T00:00:00

Link: CVE-2022-3288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-17T16:15:22.507

Modified: 2022-10-20T14:24:43.297

Link: CVE-2022-3288

cve-icon Redhat

No data.