A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2022-06-06T16:52:22

Updated: 2022-06-06T16:52:22

Reserved: 2022-05-30T00:00:00


Link: CVE-2022-1940

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-06T17:15:10.803

Modified: 2022-06-13T18:33:04.377


Link: CVE-2022-1940

JSON object: View

cve-icon Redhat Information

No data.

CWE