CVE-2022-3280 is an open redirect vulnerability in GitLab CE/EE, impacting all versions prior to 15.3.5, 15.4.4, and 15.5.2. This flaw allows an attacker to craft a seemingly legitimate GitLab URL that redirects users to arbitrary, potentially malicious, external content. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) and could lead to information disclosure (C:L) and integrity impacts (I:L) if exploited. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. While community discussion is minimal, the vulnerability has received some media coverage, primarily from GitLab's security release announcements.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.0, < 15.3.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 10.1.0, < 15.3.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.4.0, < 15.4.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.4.0, < 15.4.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.5.0, < 15.5.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.