packetstormsecurity.com
http://packetstormsecurity.com/files/163289/Atlassian-Jira-Server-Data-Center-8.16.0-Cross-Site-Scripting.html CVE-2021-26078
MEDIUM
Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-26078 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Jira Data CenterBrowse Atlassian / Jira Data Center | CVE List | Before 8.5.14 | affected |
| 8.6.0 | affected | ||
| Before 8.13.6 | affected | ||
| 8.14.0 | affected | ||
| Before 8.16.1 | affected | ||
Jira ServerBrowse Atlassian / Jira Server | CVE List | Before 8.5.14 | affected |
| 8.6.0 | affected | ||
| Before 8.13.6 | affected | ||
| 8.14.0 | affected | ||
| Before 8.16.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAtlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)ExploitDB exploitby Captain_hookNot analyzed1 file
References
3jira.atlassian.com
https://jira.atlassian.com/browse/JRASERVER-72392 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-26078