Uploaded image for project: 'Jira Service Management Data Center'
  1. Jira Service Management Data Center
  2. JSDSERVER-15294

Jira Service Management 5.12.x is vulnerable to Prototype Pollution

XMLWordPrintable

    • 6.5
    • Medium
    • CVE-2021-20085
    • Customer Report
    • XSS (Cross Site Scripting)
    • Medium

      Jira Service Management uses the backbone-query-parameters library, which is vulnerable to Prototype Pollution. An attacker can define arbitrary fields in Object.prototype and change the logic of JS scripts, which as a result can lead to XSS.

       

      Vulnerability Prototype Pollution (CVE-2021-20085)
      Affected versions 5.8.0 to 5.13.1 (this includes LTS 5.12.x versions)
      Safe versions 5.4.x LTS and 15.14.0+ versions are not affected.
      Target fix versions 5.12.9

       

       

              Unassigned Unassigned
              a64d184ae8e6 Yann
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: