CVE-2020-14169: XSS
The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14169?
CVE-2020-14169 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) attack.
How does CVE-2020-14169 affect Atlassian Jira Server and Data Center?
CVE-2020-14169 affects Atlassian Jira Server and Data Center versions prior to 8.9.1.
What is the severity level of CVE-2020-14169?
CVE-2020-14169 has a severity level of 6.1, which is considered medium.
How can remote attackers exploit CVE-2020-14169?
Remote attackers can exploit CVE-2020-14169 by injecting arbitrary HTML or JavaScript through the quick search component in Atlassian Jira Server and Data Center.
Is there a fix available for CVE-2020-14169?
Yes, a fix is available for CVE-2020-14169 in Atlassian Jira Server and Data Center versions 8.9.1 and above.