MEDIUM

CVE-2021-39878

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
5.4

Description

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

Summary dbcve.org

A stored Cross-Site Scripting (XSS) vulnerability in GitLab's Jira integration (versions 13.0 to 14.3.1) allows attackers to inject malicious JavaScript code that persists in the application and executes when users interact with the Jira integration features.

Mitigation

Update GitLab to version 14.3.2 or later to patch this vulnerability. Review and sanitize any Jira integration data already stored in the system.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.81%
Probability of exploitation in next 30 days
55.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE