-
Bug
-
Resolution: Fixed
-
Low
-
4.7.1
-
Severity 3 - Minor
-
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in API and Integrations.
Affected versions:
- version < 4.10.0
Fixed versions:
- 4.10.0
[JSDSERVER-6895] XSS in API and Integrations - CVE-2020-14166
Labels | Original: CVE-2020-14166 advisory advisory-to-release bugbounty cqt cvss-medium security xss | New: CVE-2020-14166 advisory advisory-released bugbounty cqt cvss-medium security xss |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Labels | Original: advisory advisory-to-release bugbounty cqt cvss-medium security xss | New: CVE-2020-14166 advisory advisory-to-release bugbounty cqt cvss-medium security xss |
Summary | Original: XSS in API and Integrations - CVE-PENDING | New: XSS in API and Integrations - CVE-2020-14166 |
Due Date | New: 16/Sep/2020 |
Link | New: This issue is detailed by JSDSERVER-6803 [ JSDSERVER-6803 ] |
Fix Version/s | New: 4.10.0 [ 91825 ] | |
Description | Original: Filler description. |
New:
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in API and Integrations. *Affected versions:* * version < 4.10.0 *Fixed versions:* * 4.10.0 |
Labels | New: advisory advisory-to-release bugbounty cqt cvss-medium security xss |