CVE-2020-4025: XSS
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a rdf content type.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4025?
CVE-2020-4025 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) attack.
Which software are affected by CVE-2020-4025?
Atlassian Jira Server and Data Center versions before 8.5.5, 8.6.0 to 8.8.2, and 8.9.0 to 8.9.1 are affected.
What is the severity of CVE-2020-4025?
CVE-2020-4025 has a severity rating of medium with a CVSS score of 4.8.
How can an attacker exploit CVE-2020-4025?
An attacker can exploit CVE-2020-4025 by injecting arbitrary HTML or JavaScript through a Cross-Site Scripting (XSS) attack on the attachment download resource in Atlassian Jira Server and Data Center.
Is there a fix available for CVE-2020-4025?
Yes, Atlassian has released patches for the affected versions. It is recommended to update to the patched versions to mitigate the vulnerability.