VYPR
Medium severity4.4NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026

CVE-2022-2500

CVE-2022-2500

Description

A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.

Affected products

8
  • Range: <15.0.5, <15.1.4, <15.2.1
  • GitLab Inc./GitLabllm-fuzzy6 versions
    <15.0.5, <15.1.4, <15.2.1+ 5 more
    • (no CPE)range: <15.0.5, <15.1.4, <15.2.1
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <15.0.5
    • cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <15.0.5
    • cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*
    • (no CPE)range: >=0.0, <15.0.5
  • osv-coords
    Range: < 15.0.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.