Vulnerability record · CVE-2022-3265 · published 9 November 2022
CVE-2022-3265: GitLab label colour stored XSS enables client-side actions
Gitlab · Gitlab
GitLab CE/EE contains a stored cross-site scripting flaw in the label colour setting feature, affecting versions before 15.3.5, 15.4.4, and 15.5.2. An attacker who can set a label colour can inject script that executes in a victim's browser session. Because the payload is stored, it can fire for any user who views the affected label.
Description
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 3.1 base score is 5.4 (Medium) with required privileges and user interaction, though EPSS is very high and the flaw is stored XSS in a widely deployed product.
What it is
GitLab CE/EE contains a stored cross-site scripting flaw in the label colour setting feature, affecting versions before 15.3.5, 15.4.4, and 15.5.2. An attacker who can set a label colour can inject script that executes in a victim's browser session. Because the payload is stored, it can fire for any user who views the affected label.
Impact
An attacker can run arbitrary JavaScript in a victim's GitLab session, performing actions on the victim's behalf at client side. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the GitLab web interface; the vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated user with label permissions must set the malicious colour and a victim must view the affected label.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.86326, 99.7th percentile), but the references only include vendor advisory, a broken issue link, and a HackerOne report requiring permissions, so no public exploit code is confirmed.
What to do
- Upgrade GitLab CE/EE to 15.3.5, 15.4.4, or 15.5.2 or later.
- Restrict label creation and colour editing to trusted users until patched.
- Review existing label colours for injected markup and remove suspicious values.
- Apply GitLab's vendor advisory guidance for this CVE.
Detection
- Search GitLab logs and audit events for label colour changes containing script or HTML markup.
- Inspect stored label colour values in the database for unexpected characters.
- Monitor for anomalous authenticated actions consistent with session hijacking or CSRF-style abuse.
- Review HackerOne report 1693150 for reproduction details if access is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3265.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/374976 | Broken Link |
| https://hackerone.com/reports/1693150 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3265.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/374976 | Broken Link |
| https://hackerone.com/reports/1693150 | Permissions RequiredThird Party Advisory |
Track CVE-2022-3265 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-3265), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.