Vulnerability record · CVE-2022-2230 · published 1 July 2022
CVE-2022-2230: GitLab project settings stored XSS via crafted input
Gitlab · Gitlab
GitLab CE/EE contains a stored cross-site scripting flaw in the project settings page affecting versions from 14.4 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1. An attacker with the ability to place crafted content in project settings can have arbitrary JavaScript execute in a victim's browser session. Because the payload persists in the settings page, it can fire for any user who later views that page.
Description
A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (4.8) and exploitation requires high privileges plus user interaction, but the high EPSS percentile and stored nature warrant prompt patching.
What it is
GitLab CE/EE contains a stored cross-site scripting flaw in the project settings page affecting versions from 14.4 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1. An attacker with the ability to place crafted content in project settings can have arbitrary JavaScript execute in a victim's browser session. Because the payload persists in the settings page, it can fire for any user who later views that page.
Impact
Successful exploitation lets the attacker run arbitrary JavaScript in the victim's GitLab session, enabling session or token theft, actions performed as the victim, and access to data the victim can see. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the GitLab web interface on the project settings page; the CVSS vector requires high privileges (PR:H) and user interaction (UI:R), so the attacker needs an account with sufficient rights to set the malicious content and a victim must view the affected page.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record; EPSS is high (0.57429, 99th percentile), suggesting elevated likelihood of attempted exploitation, though the references only include vendor advisory, a broken issue link, and a HackerOne report marked Permissions Required.
What to do
- Upgrade GitLab CE/EE to 14.10.5, 15.0.4, 15.1.1 or later as applicable to your release line.
- Restrict project settings modification rights to trusted maintainers and owners until patched.
- Review and remove any unexpected or suspicious content in project settings fields.
- Enable GitLab's built-in CSP and output-encoding protections and keep them enabled.
- Monitor GitLab security advisories for follow-up fixes on the affected branches.
Detection
- Audit project settings changes for injected script tags, event handlers, or javascript: URIs in stored fields.
- Search web and proxy logs for requests to project settings pages followed by anomalous script-like payloads.
- Alert on unexpected JavaScript execution or outbound requests originating from GitLab pages viewed by privileged users.
- Correlate GitLab audit events for settings edits with subsequent user session activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2230.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/364164 | Broken Link |
| https://hackerone.com/reports/1588732 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2230.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/364164 | Broken Link |
| https://hackerone.com/reports/1588732 | Permissions RequiredThird Party Advisory |
Track CVE-2022-2230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2230), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.