First published: Wed Aug 10 2022(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Data Center | <8.20.8 | |
Atlassian Jira Server | <8.20.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-36801.
The severity of CVE-2022-36801 is medium with a CVSS score of 6.1.
The affected software for CVE-2022-36801 is Atlassian Jira Server and Data Center versions before 8.20.8.
An attacker can exploit CVE-2022-36801 by injecting arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint.
Yes, the fix for CVE-2022-36801 is to upgrade to version 8.20.8 or later of Atlassian Jira Server and Data Center.