CVE-2022-36801: XSS
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36801.
What is the severity of CVE-2022-36801?
The severity of CVE-2022-36801 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2022-36801?
The affected software for CVE-2022-36801 is Atlassian Jira Server and Data Center versions before 8.20.8.
How can an attacker exploit CVE-2022-36801?
An attacker can exploit CVE-2022-36801 by injecting arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint.
Is there a fix for CVE-2022-36801?
Yes, the fix for CVE-2022-36801 is to upgrade to version 8.20.8 or later of Atlassian Jira Server and Data Center.