CVE-2021-22261: XSS
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22261?
CVE-2021-22261 is categorized as a medium severity vulnerability due to its potential impact on users.
How do I fix CVE-2021-22261?
To fix CVE-2021-22261, upgrade GitLab to version 14.0.9 or later, or 14.1.4 or later, or 14.2.2 or later.
What versions are affected by CVE-2021-22261?
CVE-2021-22261 affects all GitLab versions starting from 13.9 before 14.0.9, 14.1 before 14.1.4, and 14.2 before 14.2.2.
What type of vulnerability is CVE-2021-22261?
CVE-2021-22261 is a stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2021-22261 be exploited remotely?
Yes, CVE-2021-22261 can potentially be exploited remotely by an attacker to execute arbitrary JavaScript code.