Lucene search

K
atlassianSecurity-metrics-botJRASERVER-72059
HistoryFeb 03, 2021 - 10:53 p.m.

Stored XSS via Custom Fields on Screens Modal - CVE-2020-36234

2021-02-0322:53:01
security-metrics-bot
jira.atlassian.com
11
atlassian jira
screens modal
xss
vulnerability
cve-2020-36234
remote attackers
html
javascript
security advisory

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.2%

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view.

The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.

Affected versions:

  • version < 8.5.11
  • 8.6.0 ā‰¤ version < 8.13.3
  • 8.14.0 ā‰¤ version < 8.15.0

Fixed versions:

  • 8.5.11
  • 8.13.3
  • 8.15.0

Affected configurations

Vulners
Node
atlassianjira_data_centerRangeā‰¤8.5.0
OR
atlassianjira_data_centerRangeā‰¤8.13.0
OR
atlassianjira_data_centerRange<8.5.11
OR
atlassianjira_data_centerRange<8.13.3
OR
atlassianjira_data_centerRange<8.15.0

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.2%

Related for JRASERVER-72059