VYPR
High severity8.7NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026

CVE-2022-1190

CVE-2022-1190

Description

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Range: prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2
  • GitLab Inc./GitLabllm-fuzzy2 versions
    prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2+ 1 more
    • (no CPE)range: prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2
    • (no CPE)range: >=8.3.0, <14.7.7
  • osv-coords
    Range: >= 8.3.0, < 14.7.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.