CVE-2021-26078: XSS
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26078?
CVE-2021-26078 is a cross-site scripting (XSS) vulnerability in Jira Server and Jira Data Center.
How does CVE-2021-26078 affect Atlassian Jira?
CVE-2021-26078 affects Atlassian Jira versions up to 8.5.14 and between 8.6.0 to 8.13.6 for Data Center, and up to 8.5.14 and between 8.6.0 to 8.16.1 for Jira Server.
What is the severity of CVE-2021-26078?
CVE-2021-26078 has a severity rating of 6.1, considered medium.
How can remote attackers exploit CVE-2021-26078?
Remote attackers can exploit CVE-2021-26078 to inject arbitrary HTML or JavaScript code.
Where can I find more information about CVE-2021-26078?
You can find more information about CVE-2021-26078 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/163289/Atlassian-Jira-Server-Data-Center-8.16.0-Cross-Site-Scripting.html) and [Atlassian Jira Bug Tracker](https://jira.atlassian.com/browse/JRASERVER-72392).