The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-71184 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2020-07-01T01:35:25.329086Z
Updated: 2024-09-16T16:59:07.646Z
Reserved: 2020-06-16T00:00:00
Link: CVE-2020-14164
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-07-01T02:15:11.677
Modified: 2024-11-21T05:02:46.907
Link: CVE-2020-14164
Redhat
No data.