7.3 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
5 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
32.4%
A cross-site scripting issue has been discovered in GitLab CE/EE affecting
all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was
possible to exploit a vulnerability in setting the labels colour feature
which could lead to a stored XSS that allowed attackers to perform
arbitrary actions on behalf of victims at client side.
7.3 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
5 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
32.4%