QID 730174
Date Published: 2021-09-01
QID 730174: Atlassian Jira Server And Data Center Self-XSS Vulnerability (JRASERVER-72716)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2021-39111: Atlassian Jira Server and Data Center allow remote attackers to trick users into injecting arbitrary HTML or JavaScript via a Self Cross-Site Scripting (XSS) vulnerability in the description fields of Jira issues.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.18
Atlassian Jira Server and Data Center version from 8.6.0 prior to 8.13.10
Atlassian Jira Server and Data Center version from 8.14.0 prior to 8.18.2
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability may allow remote attackers to trick users into injecting arbitrary HTML or JavaScript via a Self Cross-Site Scripting (XSS) vulnerability.
- JRASERVER-72716 -
jira.atlassian.com/browse/JRASERVER-72716
CVEs related to QID 730174
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72716 |
|