CVE-2022-1940
Published on: Not Yet Published
Last Modified on: 06/13/2022 06:33:00 PM UTC
Certain versions of Gitlab from Gitlab contain the following vulnerability:
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues
- CVE-2022-1940 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
GitLab - GitLab version >=13.11, <14.9.5
- Affected Vendor/Software:
GitLab - GitLab version >=14.10, <14.10.4
- Affected Vendor/Software:
GitLab - GitLab version >=15.0, <15.0.1
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 3.5 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
2022/CVE-2022-1940.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
Not Found | gitlab.com text/html Inactive LinkNot Archived |
![]() |
HackerOne | hackerone.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Gitlab | Gitlab | All | All | All | All |
Application | Gitlab | Gitlab | 15.0.0 | All | All | All |
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*:
- cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*:
Discovery Credit
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-1940 : A Stored Cross-Site Scripting vulnerability in #Jira integration in GitLab EE affecting all version… twitter.com/i/web/status/1… | 2022-06-06 17:06:07 |
![]() |
CVE-2022-1940 | 2022-06-06 18:38:18 |