CVE-2019-20416: XSS
Published Jun 30, 2020
·Updated
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.
Affected Software
2 affected components
Atlassian Jira<8.3.0
Atlassian Jira Software Data Center<8.3.0
Event History
Jun 30, 2020
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20416.
2
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium with a CVSS score of 4.8.
3
Which versions of Atlassian Jira Server and Data Center are affected by this vulnerability?
The affected versions of Atlassian Jira Server and Data Center are before version 8.3.0.
4
What is the impact of this vulnerability?
This vulnerability allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability in the project configuration feature.
5
Is there a fix available for this vulnerability?
Yes, upgrading to version 8.3.0 or later of Atlassian Jira Server and Data Center will fix this vulnerability.