QID 150386
Date Published: 2021-11-11
QID 150386: Atlassian Jira Server Self-XSS Vulnerability (CVE-2021-39111)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian server allows remote attackers to trick users into injecting arbitrary HTML or JavaScript via a self-cross-site scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into fields of Jira issues.
Affected versions:
before version 8.5.18
from version 8.6.0 before 8.13.10
from version 8.14.0 before 8.18.2
Successful exploitation would lead attackers to inject HTML or JavaScript via a cross-site scripting, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72716 -
jira.atlassian.com/browse/JRASERVER-72716
CVEs related to QID 150386
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72716 |
|