CVE-2021-26083: XSS
Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26083?
CVE-2021-26083 is a vulnerability in Atlassian Jira Server and Jira Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
What is the severity of CVE-2021-26083?
The severity of CVE-2021-26083 is medium with a CVSS score of 5.4.
Which software versions are affected by CVE-2021-26083?
Atlassian Jira Server and Jira Data Center versions before 8.5.14, versions from 8.6.0 to 8.13.6, and versions from 8.14.0 to 8.16.1 are affected by CVE-2021-26083.
How can remote attackers exploit CVE-2021-26083?
Remote attackers can exploit CVE-2021-26083 by injecting arbitrary HTML or JavaScript code through a Cross-Site Scripting (XSS) vulnerability in export HTML reports in Atlassian Jira Server and Jira Data Center.
Is there a fix for CVE-2021-26083?
Yes, the fix for CVE-2021-26083 is to upgrade to Atlassian Jira Server and Jira Data Center version 8.5.14 or later, or version 8.13.6 or later, or version 8.16.1 or later.