CVE-2020-4021: XSS
Published Jun 1, 2020
·Updated
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
Affected Software
6 affected components
Atlassian Jira<7.13.16
Atlassian Jira Data Center>=8.0.0<8.5.5
Atlassian Jira Data Center>=8.6.0<8.8.1
Atlassian Jira Server>=8.0.0<8.5.5
Atlassian Jira Server>=8.6.0<8.8.1
Atlassian Jira Software Data Center<7.13.16
Event History
Jun 1, 2020
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4021.
2
What software versions are affected?
Affected versions are before 8.5.5 and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center.
3
What is the severity of CVE-2020-4021?
The severity of CVE-2020-4021 is medium with a severity value of 5.4.
4
How does CVE-2020-4021 work?
CVE-2020-4021 allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability in the XML export view.
5
How can I fix CVE-2020-4021?
To fix CVE-2020-4021, update your Atlassian Jira Server or Data Center to versions 8.5.5 or 8.8.1.