VYPR
Medium severity5.8NVD Advisory· Published Oct 5, 2021· Updated Jun 17, 2026

CVE-2021-39878

CVE-2021-39878

Description

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

Affected products

5
  • GitLab Inc./GitLabllm-fuzzy4 versions
    13.0 - 14.3.1+ 3 more
    • (no CPE)range: 13.0 - 14.3.1
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.0.0,<14.1.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.0.0,<14.1.7
    • (no CPE)range: >=13.0, <14.1.7
  • osv-coords
    Range: >= 13.0.0, < 14.1.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.