Record summary

CVE-2020-9344 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

subversion_application_lifecycle_management

Browse Atlassian / subversion_application_lifecycle_management
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMJira Subversion ALM for Enterprise <8.8.2 - Cross-Site ScriptingCVSS 6.1

Jira Subversion ALM for Enterprise before 8.8.2 contains a cross-site scripting vulnerability at multiple locations.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.

Remediation

Upgrade Jira Subversion ALM for Enterprise to version 8.8.2 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsmadrobot
Template tagscve2020cveatlassianjiraxssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:atlassian:subversion_application_lifecycle_management:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"

Source: ProjectDiscovery

References

3