CVE-2019-20414: XSS
Published Jun 29, 2020
·Updated
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
Affected Software
4 affected components
Atlassian Jira<7.13.9
Atlassian Jira Data Center>=8.0.0<8.4.2
Atlassian Jira Server>=8.0.0<8.4.2
Atlassian Jira Software Data Center<7.13.9
Event History
Jun 29, 2020
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-20414.
2
What is the severity of CVE-2019-20414?
The severity of CVE-2019-20414 is medium.
3
What versions of Atlassian Jira Server and Data Center are affected?
Versions before 7.13.9 and from 8.0.0 before 8.4.2 are affected.
4
What is the type of vulnerability in CVE-2019-20414?
The vulnerability in CVE-2019-20414 is a cross site scripting (XSS) vulnerability.
5
How can an attacker exploit CVE-2019-20414?
An attacker can exploit CVE-2019-20414 by injecting arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search.