CVE-2021-41304: XSS
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41304.
Which versions of Atlassian Jira Server and Data Center are affected by this vulnerability?
The affected versions are before version 8.13.12.
How does this vulnerability affect Atlassian Jira Server and Data Center?
This vulnerability allows anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message.
What is the severity of CVE-2021-41304?
The severity of CVE-2021-41304 is medium (6.1).
How can I fix this vulnerability?
To fix this vulnerability, update Atlassian Jira Server and Data Center to version 8.13.12 or higher.