CVE-2021-43943: XSS
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43943.
What is the severity of CVE-2021-43943?
The severity of CVE-2021-43943 is medium with a score of 4.8.
How does CVE-2021-43943 impact Atlassian Jira Service Management?
CVE-2021-43943 allows attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa.
Which versions of Atlassian Jira Service Management are affected by CVE-2021-43943?
Affected versions of Atlassian Jira Service Management Server and Data Center are up to version 4.21.0.
How can I fix CVE-2021-43943?
To fix CVE-2021-43943, upgrade Atlassian Jira Service Management to a version beyond 4.21.0.