CVE-2020-4022: XSS
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4022?
CVE-2020-4022 is a Cross-Site Scripting (XSS) vulnerability in Atlassian Jira Server and Data Center.
How does CVE-2020-4022 affect Atlassian Jira?
CVE-2020-4022 allows remote attackers to inject arbitrary HTML or JavaScript into issue attachments.
Which versions of Atlassian Jira are affected by CVE-2020-4022?
Atlassian Jira Server and Data Center before version 8.5.5, from version 8.6.0 to 8.8.2, and from version 8.9.0 to 8.9.1 are affected.
What is the severity of CVE-2020-4022?
The severity of CVE-2020-4022 is medium with a CVSS score of 6.1.
How can I fix CVE-2020-4022 in Atlassian Jira?
To fix CVE-2020-4022 in Atlassian Jira, update to version 8.5.5 or higher for Jira Server and Data Center, or to a version higher than 8.9.1 for Jira Server and Data Center.