CVE-2022-1940

HIGH

GitLab EE <14.9.5-15.0.1 - XSS

Title source: llm
STIX 2.1

Description

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

References (3)

Core 3
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/1533976

Scores

CVSS v3 7.7
EPSS 0.0018
EPSS Percentile 38.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-79
Status published
Products (2)
gitlab/gitlab 15.0.0
gitlab/gitlab 13.11.0 - 14.9.5
Published Jun 06, 2022
Tracked Since Feb 18, 2026