CVE-2021-39111: XSS
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Center - Editor pluginto a version that resolves this vulnerability.Fixed in 8.5.18 - Upgrade
Upgrade
Atlassian Jira Server and Data Center - Editor pluginto a version that resolves this vulnerability.Fixed in 8.13.10 - Upgrade
Upgrade
Atlassian Jira Server and Data Center - Editor pluginto a version that resolves this vulnerability.Fixed in 8.18.2
Event History
Frequently Asked Questions
What is CVE-2021-39111?
CVE-2021-39111 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
How does CVE-2021-39111 impact Atlassian Jira Server and Data Center?
CVE-2021-39111 allows remote attackers to inject malicious code into Atlassian Jira Server and Data Center, potentially compromising user data and system integrity.
What is the severity of CVE-2021-39111?
CVE-2021-39111 has a severity rating of medium.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-39111?
Atlassian Jira Server versions 8.6.0 to 8.13.10 and 8.14.0 to 8.18.2, as well as Atlassian Jira Data Center versions 8.6.0 to 8.13.10 and 8.14.0 to 8.18.2 are affected by CVE-2021-39111.
How can I fix CVE-2021-39111 vulnerability in Atlassian Jira Server and Data Center?
To fix the CVE-2021-39111 vulnerability, users are advised to upgrade Atlassian Jira Server and Data Center to version 8.5.18, 8.13.10, or 8.18.2 or later.