CVE-2020-14184: XSS
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14184?
CVE-2020-14184 is a Cross-Site Scripting (XSS) vulnerability in Atlassian Jira Server that allows remote attackers to inject arbitrary HTML or JavaScript via Jira issue filter export files.
Which versions of Atlassian Jira Server are affected?
Versions before 8.5.9, from 8.6.0 before 8.12.3, and from 8.13.0 before 8.13.1 of Atlassian Jira Server are affected.
How severe is CVE-2020-14184?
The severity of CVE-2020-14184 is medium, with a CVSS severity score of 5.4.
How can I fix CVE-2020-14184?
To fix CVE-2020-14184, it is recommended to upgrade Atlassian Jira Server to version 8.5.9 or later, version 8.12.3 or later, or version 8.13.1 or later.
Where can I find more information about CVE-2020-14184?
You can find more information about CVE-2020-14184 on the Atlassian Jira Server issue tracker at the following link: https://jira.atlassian.com/browse/JRASERVER-71652