First published: Tue Oct 26 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.13.12 | |
Atlassian JIRA | <8.13.12 | |
Atlassian Jira Data Center | >=8.14.0<8.20.2 | |
Atlassian Jira Server | >=8.14.0<8.20.2 | |
<8.13.12 | ||
<8.13.12 | ||
>=8.14.0<8.20.2 | ||
>=8.14.0<8.20.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-41304.
The affected versions are before version 8.13.12.
This vulnerability allows anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message.
The severity of CVE-2021-41304 is medium (6.1).
To fix this vulnerability, update Atlassian Jira Server and Data Center to version 8.13.12 or higher.