• 6.5
    • Medium
    • CVE-2021-20085
    • Customer Report
    • XSS (Cross Site Scripting)
    • Medium

      Jira Service Management uses the backbone-query-parameters library, which is vulnerable to Prototype Pollution. An attacker can define arbitrary fields in Object.prototype and change the logic of JS scripts, which as a result can lead to XSS.

       

      Vulnerability Prototype Pollution (CVE-2021-20085)
      Affected versions 5.8.0 to 5.13.1 (this includes LTS 5.12.x versions)
      Safe versions 5.4.x LTS and 15.14.0+ versions are not affected.
      Target fix versions 5.12.9

       

       

          Form Name

            [JSDSERVER-15294] Jira Service Management 5.12.x is vulnerable to Prototype Pollution

            Tim Eddelbüttel added a comment - - edited

            a64d184ae8e6, Is this issue properly "labeled" as it's not visible: on https://www.atlassian.com/trust/data-protection/vulnerabilities
            Also Affected Product(s) is missing.

            Tim Eddelbüttel added a comment - - edited a64d184ae8e6 , Is this issue properly "labeled" as it's not visible: on https://www.atlassian.com/trust/data-protection/vulnerabilities Also Affected Product(s) is missing.

              Unassigned Unassigned
              a64d184ae8e6 Yann
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: