First published: Thu Feb 24 2022(Updated: )
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Service Management | <4.21.0 | |
Atlassian Jira Service Management | <4.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-43943.
The severity of CVE-2021-43943 is medium with a score of 4.8.
CVE-2021-43943 allows attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa.
Affected versions of Atlassian Jira Service Management Server and Data Center are up to version 4.21.0.
To fix CVE-2021-43943, upgrade Atlassian Jira Service Management to a version beyond 4.21.0.