QID 730054
Date Published: 2021-04-21
QID 730054: Atlassian Jira Server Cross-Site Scripting Vulnerability(JRASERVER-72115)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.13
Atlassian Jira Server and Data Center version from 8.6.0 and prior to 8.13.5
Atlassian Jira Server and Data Center version from 8.14.0 and prior to 8.15.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.
Solution
Customers are advised to refer to JRASERVER-72115 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-72115 -
jira.atlassian.com/browse/JRASERVER-72115
CVEs related to QID 730054
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72115 |
|