CVE-2019-14996: XSS
Published Sep 11, 2019
·Updated
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
Affected Software
2 affected components
Atlassian Jira Server>=7.12.0<7.13.7
Atlassian Jira Server>=8.0.0<8.3.3
Event History
Sep 11, 2019
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-14996?
CVE-2019-14996 has a medium severity rating due to the potential for XSS attacks.
2
How do I fix CVE-2019-14996?
To fix CVE-2019-14996, upgrade Jira Server to version 7.13.7 or above, or to version 8.3.3 or above.
3
What type of vulnerability is CVE-2019-14996?
CVE-2019-14996 is classified as a cross-site scripting (XSS) vulnerability.
4
What software versions are affected by CVE-2019-14996?
CVE-2019-14996 affects Jira Server versions before 7.13.7 and versions from 8.0.0 to before 8.3.3.
5
Can CVE-2019-14996 lead to data compromise?
Yes, CVE-2019-14996 can lead to data compromise through the injection of malicious scripts.