CVE-2021-41310: XSS
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41310?
CVE-2021-41310 is a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature of Atlassian Jira Server and Data Center.
How can anonymous remote attackers exploit CVE-2021-41310?
Anonymous remote attackers can exploit CVE-2021-41310 by injecting arbitrary HTML or JavaScript through the affected feature.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-41310?
Affected versions of Atlassian Jira Server and Data Center are before 8.5.19, between 8.6.0 and 8.13.11, and between 8.14.0 and 8.19.1.
What is the severity of CVE-2021-41310?
CVE-2021-41310 has a severity rating of 6.1 (Medium).
Is there a fix available for CVE-2021-41310?
Yes, Atlassian has released patches to address the vulnerability. It is recommended to upgrade to a fixed version of Atlassian Jira Software Data Center.