Lack of sand-boxing of OpenAPI documents in GitLab CE/EE...
Critical severity
Unreviewed
Published
Nov 10, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Nov 10, 2022
Published to the GitHub Advisory Database
Nov 10, 2022
Last updated
Jan 31, 2023
Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.
References