MEDIUM
CVE-2021-39878
CVSS
5.4
Description
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
Summary dbcve.org
A stored Cross-Site Scripting (XSS) vulnerability in GitLab's Jira integration (versions 13.0 to 14.3.1) allows attackers to inject malicious JavaScript code that persists in the application and executes when users interact with the Jira integration features.
Mitigation
Update GitLab to version 14.3.2 or later to patch this vulnerability. Review and sanitize any Jira integration data already stored in the system.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.81%
Probability of exploitation in next 30 days
55.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.