-
Bug
-
Resolution: Fixed
-
Low
-
4.7.1
-
Severity 3 - Minor
-
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in API and Integrations.
Affected versions:
- version < 4.10.0
Fixed versions:
- 4.10.0
[JSDSERVER-6895] XSS in API and Integrations - CVE-2020-14166
Labels | Original: CVE-2020-14166 advisory advisory-to-release bugbounty cqt cvss-medium security xss | New: CVE-2020-14166 advisory advisory-released bugbounty cqt cvss-medium security xss |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Labels | Original: advisory advisory-to-release bugbounty cqt cvss-medium security xss | New: CVE-2020-14166 advisory advisory-to-release bugbounty cqt cvss-medium security xss |
Summary | Original: XSS in API and Integrations - CVE-PENDING | New: XSS in API and Integrations - CVE-2020-14166 |
Due Date | New: 16/Sep/2020 |
Link | New: This issue is detailed by JSDSERVER-6803 [ JSDSERVER-6803 ] |
Fix Version/s | New: 4.10.0 [ 91825 ] | |
Description | Original: Filler description. |
New:
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in API and Integrations. *Affected versions:* * version < 4.10.0 *Fixed versions:* * 4.10.0 |
Labels | New: advisory advisory-to-release bugbounty cqt cvss-medium security xss |
Does Atlassian Jira Service Desk Appliance version number and Atlassian Jira Service Desk Server version number match up, or, are separate version numbers specific to each the Appliance version and Server version?
Just need to know as I can not get Atlassian Jira Service Desk Server version, while Atlassian Service Desk Application version number is displayed.