First published: Mon Jun 29 2020(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <7.13.9 | |
Atlassian Jira Data Center | >=8.0.0<8.4.2 | |
Atlassian Jira Server | >=8.0.0<8.4.2 | |
Atlassian Jira Software Data Center | <7.13.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-20414.
The severity of CVE-2019-20414 is medium.
Versions before 7.13.9 and from 8.0.0 before 8.4.2 are affected.
The vulnerability in CVE-2019-20414 is a cross site scripting (XSS) vulnerability.
An attacker can exploit CVE-2019-20414 by injecting arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search.