vendor:
Jira Server/Data Center
by:
CAPTAIN_HOOK
6,1
CVSS
MEDIUM
Reflected Cross-Site Scripting (XSS)
79
CWE
Product Name: Jira Server/Data Center
Affected Version From: versions < 8.5.14, 8.6.0 ≤ version < 8.13.6, 8.14.0 ≤ version < 8.16.1
Affected Version To: None
Patch Exists: YES
Related CWE: CVE-2021-26078
CPE: a:atlassian:jira_server
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: ANY
2021
Atlassian Jira Server/Data Center 8.16.0 – Reflected Cross-Site Scripting (XSS)
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via across site scripting (XSS) vulnerability.
Mitigation:
Upgrade to version 8.5.14, 8.13.6, 8.16.1 or 8.17.0