CVE-2018-13395

MEDIUM

Atlassian Jira < 7.6.8, 7.7.0-7.7.5, 7.8.0-7.8.5, 7.9.0-7.9.3, 7.10.0-7.10.3 - Cross-Site Scripting in Epic Colour Field

Title source: llm
STIX 2.1

Description

Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the epic colour field of an issue while an issue is being moved.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/JRASERVER-67848

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
atlassian/jira < 7.6.8
atlassian/jira_server 7.7.0 - 7.7.5
Published Aug 28, 2018
Tracked Since Feb 18, 2026