CVE-2018-20232: XSS
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the upprojectid widget preference setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20232?
CVE-2018-20232 is classified as a high severity vulnerability due to its potential for remote code execution via cross site scripting.
How do I fix CVE-2018-20232?
To fix CVE-2018-20232, upgrade Jira to version 7.6.11 or to any version between 7.7.0 and 7.13.1, inclusive.
Who is affected by CVE-2018-20232?
CVE-2018-20232 affects Atlassian Jira versions prior to 7.6.11 and versions between 7.7.0 and 7.13.1.
What type of vulnerability is CVE-2018-20232?
CVE-2018-20232 is a cross site scripting (XSS) vulnerability that allows attackers to inject arbitrary HTML or JavaScript.
Can CVE-2018-20232 be exploited remotely?
Yes, CVE-2018-20232 can be exploited remotely, allowing attackers to manipulate URL content and execute scripts.