CVE-2022-1940: XSS
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1940?
CVE-2022-1940 is a Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1.
How does CVE-2022-1940 impact GitLab EE?
CVE-2022-1940 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues.
What is the severity of CVE-2022-1940?
CVE-2022-1940 has a severity rating of high.
How can I fix CVE-2022-1940 in GitLab EE?
To fix CVE-2022-1940, it is recommended to update GitLab to version 14.9.5, 14.10.4, or 15.0.1 or later.
Where can I find more information about CVE-2022-1940?
You can find more information about CVE-2022-1940 on the GitLab CVE page: https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.json