CVE-2020-4024: XSS
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4024?
CVE-2020-4024 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in issue attachments.
How does CVE-2020-4024 affect Atlassian Jira?
CVE-2020-4024 affects Atlassian Jira Server versions before 8.5.5, and Jira Data Center versions from 8.6.0 to 8.8.2, and from 8.9.0 to 8.9.1.
What is the severity of CVE-2020-4024?
CVE-2020-4024 has a severity rating of medium, with a CVSS score of 5.4.
How can remote attackers exploit CVE-2020-4024?
Remote attackers can exploit CVE-2020-4024 by uploading issue attachments containing malicious HTML or JavaScript code, which will be executed when other users download the attachments.
Is there a fix for CVE-2020-4024?
Yes, Atlassian has released patches to fix CVE-2020-4024. Users should upgrade to Jira Server 8.5.5 or higher, or Jira Data Center 8.8.2, 8.9.1, or higher to mitigate the vulnerability.