CVE-2022-1940
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a…
Does this matter?
Lower severity and a low EPSS score (6.05%). Track it; it rarely justifies an emergency change on its own.
Description
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 6.05% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.jsonPatch, Third Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/359142Broken Link
- https://hackerone.com/reports/1533976Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.jsonPatch, Third Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/359142Broken Link
- https://hackerone.com/reports/1533976Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.