Medium severity4.3NVD Advisory· Published May 19, 2022· Updated Jun 17, 2026
CVE-2022-1416
CVE-2022-1416
Description
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 4 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=1.0.2,<14.8.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=1.0.2,<14.8.6
- cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*
- (no CPE)range: >=1.0.2, <14.8.6
- Range: from 1.0.2 before 14.8.6, from 14.9.0 before 14.9.4, and from 14.10.0 before 14.10.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/gitlab/-/issues/342988nvdExploitIssue TrackingTechnical DescriptionThird Party Advisory
- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1416.jsonnvdThird Party Advisory
- hackerone.com/reports/1362405nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.