-
Public Security Vulnerability
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
8.5.0, 8.13.0
-
None
-
4.8
-
Medium
-
CVE-2020-36234
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view.
The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
Affected versions:
- version < 8.5.11
- 8.6.0 ≤ version < 8.13.3
- 8.14.0 ≤ version < 8.15.0
Fixed versions:
- 8.5.11
- 8.13.3
- 8.15.0
[JRASERVER-72059] Stored XSS via Custom Fields on Screens Modal - CVE-2020-36234
CVE ID | New: CVE-2020-36234 |
Labels | Original: CVE-2020-36234 advisory advisory-to-release dont-import security | New: CVE-2020-36234 advisory advisory-released dont-import security |
Labels | Original: advisory advisory-to-release dont-import security | New: CVE-2020-36234 advisory advisory-to-release dont-import security |
Summary | Original: Stored XSS via Custom Fields on Screens Modal - CVE-PENDING | New: Stored XSS via Custom Fields on Screens Modal - CVE-2020-36234 |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Summary | Original: Stored XSS via Custom Fields on Screens Modal | New: Stored XSS via Custom Fields on Screens Modal - CVE-PENDING |
Description |
Original:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view.
The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. **Affected versions:** * version < 8.5.11 * 8.6.0 ≤ version < 8.13.3 * 8.14.0 ≤ version < 8.15.0 **Fixed versions:** * 8.5.11 * 8.13.3 * 8.15.0 |
New:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view.
The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. *Affected versions:* * version < 8.5.11 * 8.6.0 ≤ version < 8.13.3 * 8.14.0 ≤ version < 8.15.0 *Fixed versions:* * 8.5.11 * 8.13.3 * 8.15.0 |
Description |
Original:
This vulnerability affects certain versions of Atlassian Jira Server. Please describe the impact of the vulnerability here. No known vulnerability could be read off of the parent. |
New:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view.
The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. **Affected versions:** * version < 8.5.11 * 8.6.0 ≤ version < 8.13.3 * 8.14.0 ≤ version < 8.15.0 **Fixed versions:** * 8.5.11 * 8.13.3 * 8.15.0 |
Labels | New: advisory advisory-to-release dont-import security |