First published: Mon Jul 13 2020(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Data Center | >=8.2.1<8.7.0 | |
Atlassian Jira Server | >=8.2.1<8.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20900 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module.
Remote attackers can exploit CVE-2019-20900 by injecting arbitrary HTML or JavaScript using a cross-site scripting (XSS) vulnerability in the Add Field module of Atlassian Jira Server and Data Center.
Versions of Atlassian Jira Server and Data Center before version 8.7.0 are affected by CVE-2019-20900.
The severity of CVE-2019-20900 is medium, with a severity score of 4.8.
To fix CVE-2019-20900, upgrade Atlassian Jira Server and Data Center to version 8.7.0 or later.