First published: Wed Jul 01 2020(Updated: )
The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <8.9.1 | |
Atlassian Jira Software Data Center | <8.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14169 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) attack.
CVE-2020-14169 affects Atlassian Jira Server and Data Center versions prior to 8.9.1.
CVE-2020-14169 has a severity level of 6.1, which is considered medium.
Remote attackers can exploit CVE-2020-14169 by injecting arbitrary HTML or JavaScript through the quick search component in Atlassian Jira Server and Data Center.
Yes, a fix is available for CVE-2020-14169 in Atlassian Jira Server and Data Center versions 8.9.1 and above.