CVE-2020-14173: XSS
The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14173?
CVE-2020-14173 is a cross-site scripting (XSS) vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via the file upload feature.
What is the severity of CVE-2020-14173?
The severity of CVE-2020-14173 is medium with a severity score of 5.4.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2020-14173?
The affected versions of Atlassian Jira Server and Data Center are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
How can a remote attacker exploit the CVE-2020-14173 vulnerability?
A remote attacker can exploit the CVE-2020-14173 vulnerability by injecting arbitrary HTML or JavaScript through the file upload feature in Atlassian Jira Server and Data Center.
Is there a fix available for CVE-2020-14173?
Yes, you can fix the CVE-2020-14173 vulnerability by upgrading Atlassian Jira Server and Data Center to version 8.5.4 or later, version 8.6.2 or later, or version 8.7.1 or later.