Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43082 | Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account. |
Thu, 01 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-01T19:23:10.307Z
Reserved: 2022-10-27T00:00:00.000Z
Link: CVE-2022-3726
Updated: 2024-08-03T01:20:57.132Z
Status : Modified
Published: 2022-11-10T00:15:22.257
Modified: 2024-11-21T07:20:06.940
Link: CVE-2022-3726
No data.
OpenCVE Enrichment
No data.
EUVD