First published: Tue Aug 13 2019(Updated: )
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Server | >=7.7<7.13.6 | |
Atlassian Server | >=8.0.0<8.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8444 has a medium severity rating due to its potential for exploitation via cross-site scripting.
To mitigate CVE-2019-8444, upgrade to Jira version 7.13.6 or version 8.3.2 and above.
CVE-2019-8444 affects Jira Server versions prior to 7.13.6 and versions between 8.0.0 and 8.3.2.
CVE-2019-8444 allows remote attackers to perform cross-site scripting (XSS) attacks.
Yes, CVE-2019-8444 exposes user input fields to the risk of injection of arbitrary HTML or JavaScript.