PT-2021-22724 · Atlassian+1 · Jira+1

Ooooooo_Q

·

Published

2021-10-05

·

Updated

2024-03-06

·

CVE-2021-39878

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab versions 13.0 through 14.3.1
Description: A stored Reflected Cross-Site Scripting issue in the Jira integration allows an attacker to execute arbitrary javascript code.
Recommendations: For GitLab versions 13.0 through 14.3.1, update to a version later than 14.3.1 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39878
CVE-2021-39878

Affected Products

Gitlab
Jira