- 
    
Public Security Vulnerability
 - 
    Resolution: Fixed
 - 
    
Low
 - 
    8.5.13, 8.13.5, 8.16.0
 - 
    None
 
- 
        3.5
 - 
        Low
 - 
        CVE-2021-26082
 
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in XML Export.
The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0.
*Affected versions:*
- version < 8.5.14
 - 8.6.0 ≤ version < 8.13.6
 - 8.14.0 ≤ version < 8.17.0
 
*Fixed versions:*
- 8.5.14
 - 8.13.6
 - 8.17.0