CVE-2021-26083
Summary
| CVE | CVE-2021-26083 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-20 04:15:00 UTC |
| Updated | 2022-03-30 13:29:00 UTC |
| Description | Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [JRASERVER-72213] The name of a filter can be used to XSS users who open an "Export HTML Report" - CVE-2021-26083 - Create and track feature requests for Atlassian products. |
MISC |
jira.atlassian.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150381 Atlassian Jira Multiple Vulnerabilities (JULY 2021)
- 730144 Atlassian Jira Multiple Vulnerabilities (JRASERVER-72213, JRASERVER-72499)