CVE-2020-36234: XSS
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-36234.
What is the severity of CVE-2020-36234?
The severity of CVE-2020-36234 is medium with a severity value of 4.8.
Which versions of Atlassian Jira Server and Data Center are affected?
Affected versions of Atlassian Jira Server and Data Center are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
How can remote attackers exploit CVE-2020-36234?
Remote attackers can exploit CVE-2020-36234 by injecting arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view of Atlassian Jira Server and Data Center.
Is there a fix for CVE-2020-36234?
Yes, the fix for CVE-2020-36234 is to upgrade to version 8.5.11 or later for Atlassian Jira Server and Data Center.