Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86mr-824x-hfxf

Опубликовано: 07 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

EPSS

Процентиль: 79%
0.01352
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.7
ubuntu
около 3 лет назад

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 7.7
nvd
около 3 лет назад

A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues

CVSS3: 7.7
debian
около 3 лет назад

A Stored Cross-Site Scripting vulnerability in Jira integration in Git ...

CVSS3: 7.7
fstec
около 3 лет назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab Enterprise Edition, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код JavaScript

EPSS

Процентиль: 79%
0.01352
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79