CVE-2020-36236: XSS
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36236?
CVE-2020-36236 is a Cross-Site Scripting (XSS) vulnerability in Atlassian Jira Server and Data Center.
How does CVE-2020-36236 affect Atlassian Jira Server?
CVE-2020-36236 affects Atlassian Jira Server versions before 8.5.11, from version 8.6.0 to 8.13.3, and from version 8.14.0 to 8.15.0.
How does CVE-2020-36236 affect Atlassian Jira Data Center?
CVE-2020-36236 affects Atlassian Jira Data Center versions from 8.6.0 to 8.13.3, and from 8.14.0 to 8.15.0.
What is the severity of CVE-2020-36236?
CVE-2020-36236 has a severity value of 6.1, which is considered medium severity.
Is there a fix available for CVE-2020-36236?
Yes, Atlassian has released fixes for CVE-2020-36236. Users should upgrade to a fixed version to mitigate the vulnerability.