CVE-2022-3573
GitLab vulnerability analysis and mitigation

Overview

A Cross-Site Scripting (XSS) vulnerability was discovered in GitLab CE/EE affecting versions 15.4 through 15.7.2. The vulnerability, identified as CVE-2022-3573, was discovered in October 2022 and patched in January 2023. The issue affects self-hosted GitLab instances running without strict Content Security Policy (CSP) (GitLab Release, CVE Mitre).

Technical details

The vulnerability stems from improper filtering of query parameters in the wiki changes page. The issue occurs in the app/views/projects/diffs/_diffs.html.haml file where request.query_parameters is used instead of safe_params to pass parameters to link_to. This implementation allows arbitrary parameters to be passed, including protocol or host parameters, enabling potential javascript: URL injections. The vulnerability has been assigned a CVSS score of 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) indicating medium severity (GitLab Release).

Impact

When exploited, this vulnerability allows attackers to execute arbitrary JavaScript code in the victim's browser context on self-hosted instances running without strict CSP. This could potentially lead to performing actions on behalf of the affected user and compromise their account security (GitLab Issue).

Exploitability

The vulnerability requires an attacker to have low privileges (ability to create a project) and user interaction. The attack can be performed over the internet, with relatively low complexity. The exploit involves crafting specific URLs with malicious parameters that can bypass the existing security controls on instances without strict CSP (GitLab Issue).

Mitigation and workarounds

GitLab has addressed this vulnerability in versions 15.5.7, 15.6.4, and 15.7.2. Organizations running affected versions should upgrade immediately to one of these patched versions. Additionally, implementing strict Content Security Policy (CSP) serves as an effective mitigation measure against this type of attack (GitLab Release).

Community reactions

The vulnerability was responsibly disclosed through GitLab's HackerOne bug bounty program by security researcher ryotak. GitLab acknowledged the issue and addressed it in their security release, demonstrating their commitment to maintaining security standards (GitLab Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • gitlab-rails-19.1
NoYesAug 17, 2026
CVE-2026-10053HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 23, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management