-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
8.13.13, 8.20.1
-
None
-
6.1
-
Medium
-
CVE-2021-43942
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website.
The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.
Affected versions:
- version < 8.13.15
- 8.14.0 ≤ version < 8.20.3
Fixed versions:
- 8.13.15
- 8.20.3
- 8.21.0
- causes
-
JRASERVER-73212 Submitting an issue collector on a non-same origin site results in HTTP 404
- Closed
- mentioned in
-
Page Loading...