-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 7.9.0
-
Component/s: Security - XSS
-
Severity 3 - Minor
Affected versions of Bitbucket Server and Data Center use a version of jQuery that is vulnerable to CVE-2020-11022 and CVE-2020-11023. These allow an unauthenticated attacker to inject Javascript into the application via Cross-Site Scripting (XSS) vulnerabilities.
A jquery patch has been applied for Bitbucket versions >= 7.10.0.
- relates to
-
BSERV-13679 Update Jquery used on Bitbucket
-
- Closed
-
- mentioned in
-
Page Loading...