An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacker specified URL.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/349422 | third party advisory broken link |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0283.json | vendor advisory |