The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

      Affected versions

      • version < 8.5.4
      • 8.6.0 ≤ version ≤ 8.7.0
      • 8.7.0 ≤ version < 8.7.1

      Fixed versions

      • 8.5.4
      • 8.7.1
      • 8.8.0

            [JRASERVER-70814] Stored XSS via malicious file upload - CVE-2020-14173

            David Black made changes -
            Labels Original: CVE-2020-14173 advisory advisory-to-release bugbounty cvss-high security sxss xss New: CVE-2020-14173 advisory advisory-released bugbounty cvss-high security sxss xss

            Tobias added a comment -

            Will there be a fix for LTS versions above 8.5.4?

            Tobias added a comment - Will there be a fix for LTS versions above 8.5.4?
            Dave (Inactive) made changes -
            Description Original: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

            *Affected versions*
             * version < 8.5.4
             * 8.6.0 ≤ version < 8.7.0
             * 8.7.0 ≤ version < 8.7.1

            *Fixed versions*
             * 8.5.4
             * 8.7.1
             * 8.8.0
            New: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

            *Affected versions*
             * version < 8.5.4
             * 8.6.0 ≤ version ≤ 8.7.0
             * 8.7.0 ≤ version < 8.7.1

            *Fixed versions*
             * 8.5.4
             * 8.7.1
             * 8.8.0
            Dave (Inactive) made changes -
            Description Original: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

            *Affected versions*
             * version < 8.5.4
             * 8.6.0 ≤ version < 8.6.2
             * 8.7.0 ≤ version < 8.7.1

            *Fixed versions*
             * 8.5.4
             * 8.6.2
             * 8.7.1
             * 8.8.0
            New: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

            *Affected versions*
             * version < 8.5.4
             * 8.6.0 ≤ version < 8.7.0
             * 8.7.0 ≤ version < 8.7.1

            *Fixed versions*
             * 8.5.4
             * 8.7.1
             * 8.8.0
            Dave (Inactive) made changes -
            Fix Version/s Original: 8.6.2 [ 91193 ]
            AB made changes -
            Summary Original: Stored XSS via malicious file upload New: Stored XSS via malicious file upload - CVE-2020-14173
            AB made changes -
            Labels Original: advisory advisory-to-release bugbounty cve-in-progress cvss-high security sxss xss New: CVE-2020-14173 advisory advisory-to-release bugbounty cvss-high security sxss xss
            AB made changes -
            Labels Original: advisory advisory-to-release bugbounty cvss-high security sxss xss New: advisory advisory-to-release bugbounty cve-in-progress cvss-high security sxss xss

            trtherrien added a comment -

            Does version 7.13.13 require an update and would we have to go all the way to 8.5.4?

            trtherrien added a comment - Does version 7.13.13 require an update and would we have to go all the way to 8.5.4?
            Mahtab made changes -
            Affects Version/s New: 8.5.1 [ 89499 ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              14 Start watching this issue

                Created:
                Updated:
                Resolved: