CVE-2021-43945: XSS
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-43945.
What is the severity of CVE-2021-43945?
CVE-2021-43945 has a severity of medium.
What is the affected software for CVE-2021-43945?
The affected software for CVE-2021-43945 is Atlassian Jira Server and Data Center.
How can remote attackers exploit CVE-2021-43945?
Remote attackers with Roadmaps Administrator permissions can exploit CVE-2021-43945 by injecting arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint.
Is there a fix available for CVE-2021-43945?
Yes, a fix is available for CVE-2021-43945. It is recommended to upgrade to a version above 8.20.3.