CVE-2021-39878: XSS
Published Oct 5, 2021
·Updated
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
Affected Software
6 affected components
GitLab GitLab>=13.0.0<14.1.7
GitLab GitLab>=13.0.0<14.1.7
GitLab GitLab>=14.2.0<14.2.5
GitLab GitLab>=14.2.0<14.2.5
GitLab GitLab>=14.3.0<14.3.1
GitLab GitLab>=14.3.0<14.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.3.1
Event History
Oct 5, 2021
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-39878?
CVE-2021-39878 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-39878?
To fix CVE-2021-39878, upgrade GitLab to version 14.3.2 or later.
3
What impact does CVE-2021-39878 have on affected systems?
CVE-2021-39878 allows attackers to execute arbitrary JavaScript code on affected GitLab instances, leading to potential data compromise.
4
Which versions of GitLab are affected by CVE-2021-39878?
CVE-2021-39878 affects GitLab versions from 13.0 up to and including 14.3.1.
5
Is CVE-2021-39878 a cross-site scripting vulnerability?
Yes, CVE-2021-39878 is a stored reflected cross-site scripting vulnerability.