QID 730082

Date Published: 2021-05-18

QID 730082: Atlassian Jira Server Cross-Site Scripting Vulnerability (JRASERVER-72392)

Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

Affected by below vulnerability:
CVE-2021-26078: Vulnerability in Search Template Leads to Reflected XSS JIRA Software Server

Affected version:
Atlassian Jira Server version prior to 8.5.14
Atlassian Jira Server 8.6.0 version prior to 8.13.6
Atlassian Jira Server 8.14.0 version prior to8.16.1

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.

Successful exploitation could affects integrity, confidentiality and availability.

  • CVSS V3 rated as Medium - 4.7 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to JRASERVER-72392 for updates pertaining to this vulnerability.

    Vendor References

    CVEs related to QID 730082

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72392 URL Logo jira.atlassian.com/browse/JRASERVER-72392