Medium severity4.4NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026
CVE-2022-2500
CVE-2022-2500
Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1. A stored XSS flaw in job error messages allows attackers to perform arbitrary actions on behalf of victims at client side.
Affected products
8- Range: <15.0.5, <15.1.4, <15.2.1
<15.0.5, <15.1.4, <15.2.1+ 5 more
- (no CPE)range: <15.0.5, <15.1.4, <15.2.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <15.0.5
- cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <15.0.5
- cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*
- (no CPE)range: >=0.0, <15.0.5
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2500.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/363725nvdBroken LinkVendor Advisory
- hackerone.com/reports/1579645nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.