-
Public Security Vulnerability
-
Resolution: Fixed
-
Medium
-
5.8.0, 5.8.1, 5.9.0, 5.8.2, 5.9.1, 5.10.0, 5.9.2, 5.11.0, 5.10.1, 5.10.2, 5.12.0, 5.11.1, 5.9.3, 5.8.3, 5.13.0, 5.10.3, 5.11.2, 5.11.3, 5.12.1, 5.11.4, 5.12.2, 5.13.1, 5.12.3, 5.12.4, 5.13.2, 5.12.6, 5.12.5, 5.12.7, 5.12.8
-
None
-
None
-
6.5
-
Medium
-
CVE-2021-20085
-
Customer Report
-
XSS (Cross Site Scripting)
-
Medium
Jira Service Management uses the backbone-query-parameters library, which is vulnerable to Prototype Pollution. An attacker can define arbitrary fields in Object.prototype and change the logic of JS scripts, which as a result can lead to XSS.
Vulnerability | Prototype Pollution (CVE-2021-20085) |
Affected versions | 5.8.0 to 5.13.1 (this includes LTS 5.12.x versions) |
Safe versions | 5.4.x LTS and 15.14.0+ versions are not affected. |
Target fix versions | 5.12.9 |
- mentioned in
-
Page Loading...