← volver
CVE-2022-3573mediumexplotación observadaCWE-79

CVE-2022-3573

35Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Attendcvss 5.4epss 0.6%
de la publicación al arma
Publicada en NVD12 ene
VulnCheck+734d
probabilidad de explotación
0.6%top 55% de las CVE
explotación observada
VulnCheck
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Productos afectados
GitLab · GitLab