Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72597

Stored XSS via Custom Fields creation on AssociateFieldToScreens page - CVE-2021-39117

    • 4.8
    • Medium
    • CVE-2021-39117

      Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the Custom Fields creation feature on the AssociateFieldToScreens page.

      This bug was introduced in version 8.15.0, and is fixed in version 8.18.0.

      *Affected versions:*

      • 8.15.0 ≤ version < 8.18.0

          Form Name

            [JRASERVER-72597] Stored XSS via Custom Fields creation on AssociateFieldToScreens page - CVE-2021-39117

            Chris Martin added a comment - - edited

            Hi - are there any plans to backport this fix to 8.13 (LTS)?

             

            Update: ignore the above, it appears as though the description was updated to indicate this was previously resolved in 8.13.9 - thanks!

            Chris Martin added a comment - - edited Hi - are there any plans to backport this fix to 8.13 (LTS)?   Update: ignore the above, it appears as though the description was updated to indicate this was previously resolved in 8.13.9 - thanks!

            AB added a comment - - edited

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 4.8 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required High
            User Interaction Required

            Scope Metric

            Scope Changed

            Impact Metrics

            Confidentiality Low
            Integrity Low
            Availability None

             

            AB added a comment - - edited This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 4.8 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required High User Interaction Required Scope Metric Scope Changed Impact Metrics Confidentiality Low Integrity Low Availability None  

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: