CVE-2022-2428: GitLab

High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

Affected products

  • GitLab GitLab: before 15.1.6 (fixed in 15.1.6); from 15.2, before 15.2.4 (fixed in 15.2.4); from 15.3, before 15.3.2 (fixed in 15.3.2)

Published 2022-10-17. Last modified 2026-06-17.