CVE-2022-3726 is a critical vulnerability in GitLab CE/EE versions 12.6 through 15.3.4, 15.4 through 15.4.3, and 15.5 through 15.5.1. It stems from a lack of sandboxing in OpenAPI documents, allowing an attacker to trick a user into clicking a malicious Swagger OpenAPI viewer. This can lead to the execution of HTTP requests impacting the victim's account. This vulnerability carries a CVSS score of 9.0 (CRITICAL), indicating a network-based attack with low complexity, requiring user interaction, and resulting in high confidentiality, integrity, and availability impacts. The FAUCET Risk Score is 90/100. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered significant community discussion, with 11 mentions, and has been covered by GitLab's security release announcements.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.6.0, < 15.3.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 12.6.0, < 15.3.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.4.0, < 15.4.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.4.0, < 15.4.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.5.0, < 15.5.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.