High severity7.7NVD Advisory· Published Jun 6, 2022· Updated Jun 17, 2026
CVE-2022-1940
CVE-2022-1940
Description
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira Issues
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1
- Range: >=13.11, <14.9.5
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1940.jsonnvdPatchThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/359142nvdBroken Link
- hackerone.com/reports/1533976nvdPermissions Required
News mentions
0No linked articles in our index yet.