First published: Mon Feb 15 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.5.11 | |
Atlassian Data Center | >=8.6.0<8.13.3 | |
Atlassian JIRA | <8.5.11 | |
Atlassian Jira Data Center | >=8.14.0<8.15.0 | |
Atlassian Jira Server | >=8.6.0<8.13.3 | |
Atlassian Jira Server | >=8.14.0<8.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-36234.
The severity of CVE-2020-36234 is medium with a severity value of 4.8.
Affected versions of Atlassian Jira Server and Data Center are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
Remote attackers can exploit CVE-2020-36234 by injecting arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view of Atlassian Jira Server and Data Center.
Yes, the fix for CVE-2020-36234 is to upgrade to version 8.5.11 or later for Atlassian Jira Server and Data Center.