First published: Mon Jun 07 2021(Updated: )
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.5.14 | |
Atlassian Data Center | >=8.6.0<8.13.6 | |
Atlassian Data Center | >=8.14.0<8.16.1 | |
Atlassian Jira | <8.5.14 | |
Atlassian Server | >=8.6.0<8.13.6 | |
Atlassian Server | >=8.14.0<8.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26078 is a cross-site scripting (XSS) vulnerability in Jira Server and Jira Data Center.
CVE-2021-26078 affects Atlassian Jira versions up to 8.5.14 and between 8.6.0 to 8.13.6 for Data Center, and up to 8.5.14 and between 8.6.0 to 8.16.1 for Jira Server.
CVE-2021-26078 has a severity rating of 6.1, considered medium.
Remote attackers can exploit CVE-2021-26078 to inject arbitrary HTML or JavaScript code.
You can find more information about CVE-2021-26078 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/163289/Atlassian-Jira-Server-Data-Center-8.16.0-Cross-Site-Scripting.html) and [Atlassian Jira Bug Tracker](https://jira.atlassian.com/browse/JRASERVER-72392).