Uploaded image for project: 'Jira Service Management Data Center'
  1. Jira Service Management Data Center
  2. JSDSERVER-15294

Jira Service Management 5.12.x is vulnerable to Prototype Pollution

XMLWordPrintable

    • 6.5
    • Medium
    • CVE-2021-20085
    • Customer Report
    • XSS (Cross Site Scripting)
    • Medium

      Jira Service Management uses the backbone-query-parameters library, which is vulnerable to Prototype Pollution. An attacker can define arbitrary fields in Object.prototype and change the logic of JS scripts, which as a result can lead to XSS.

       

      Vulnerability Prototype Pollution (CVE-2021-20085)
      Affected versions 5.8.0 to 5.13.1 (this includes LTS 5.12.x versions)
      Safe versions 5.4.x LTS and 15.14.0+ versions are not affected.
      Target fix versions 5.12.9

       

       

            Unassigned Unassigned
            a64d184ae8e6 Yann
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: