-
Bug
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
8.5.1, 8.5.3
-
8.05
-
Severity 2 - Major
-
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the WYSIWYG editor.
The affected versions are before 8.5.9, and from version 8.6.0 before 8.8.2.
Affected versions:
- version < 8.5.9
- 8.6.0 ≤ version < 8.8.2
Fixed versions:
- 8.5.9
- 8.8.2
- 8.9.0
[JRASERVER-71184] XSS in WYSIWYG editor via pasted code - CVE-2020-14164
Remote Link | New: This issue links to "Page (Confluence)" [ 509303 ] |
Description |
Original:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the WYSIWYG editor.
*Affected versions:* * version < 8.8.2 *Fixed versions:* * 8.8.2 * 8.9.0 |
New:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the WYSIWYG editor.
The affected versions are before 8.5.9, and from version 8.6.0 before 8.8.2. *_Affected versions:_* * version < 8.5.9 * 8.6.0 ≤ version < 8.8.2 *_Fixed versions:_* * 8.5.9 * 8.8.2 * 8.9.0 |
Summary | Original: XSS in Issue - Fields - CVE-2020-14164 | New: XSS in WYSIWYG editor via pasted code - CVE-2020-14164 |
Description |
Original:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in WYSIWYG editor.
*Affected versions:* * version < 8.8.2 *Fixed versions:* * 8.8.2 * 8.9.0 |
New:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the WYSIWYG editor.
*Affected versions:* * version < 8.8.2 *Fixed versions:* * 8.8.2 * 8.9.0 |
Fixed in Long Term Support Release/s | New: [Download 8.5|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Fix Version/s | New: 8.5.9 [ 92910 ] |
Hi, this is now fixed in 8.5 Enterprise LTS, in version 8.5.9.