CVE-2016-4318: XSS
Published Apr 10, 2017
·Updated
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
Affected Software
1 affected component
Atlassian Jira<=7.1.8
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4318?
CVE-2016-4318 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2016-4318?
To fix CVE-2016-4318, upgrade Atlassian JIRA Server to version 7.1.9 or later.
3
What does CVE-2016-4318 affect?
CVE-2016-4318 affects Atlassian JIRA Server versions prior to 7.1.9.
4
What type of vulnerability is CVE-2016-4318?
CVE-2016-4318 is an XSS (Cross-Site Scripting) vulnerability that affects JIRA regarding role names.
5
Is CVE-2016-4318 easy to exploit?
CVE-2016-4318 can be exploited by attackers who can control or manipulate project role names in JIRA.