CVE-2021-26080: XSS
EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26080?
CVE-2021-26080 is a cross-site scripting (XSS) vulnerability in EditworkflowScheme.jspa in Jira Server and Jira Data Center.
How does CVE-2021-26080 affect Atlassian Jira Data Center?
CVE-2021-26080 affects Atlassian Jira Data Center versions between 8.6.0 to 8.13.6, and between 8.14.0 to 8.16.1.
How does CVE-2021-26080 affect Atlassian Jira Server?
CVE-2021-26080 affects Atlassian Jira Server versions up to 8.5.14, and between 8.6.0 to 8.13.6, and between 8.14.0 to 8.16.1.
What is the severity of CVE-2021-26080?
CVE-2021-26080 has a severity rating of 6.1 (Medium).
How can I fix CVE-2021-26080?
To fix CVE-2021-26080, upgrade Atlassian Jira Server or Jira Data Center to version 8.5.14 or higher.