CVE-2021-26078
Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
El componente number range searcher en Jira Server y Jira Data Center versiones anteriores a 8.5.14, desde versiones 8.6.0 anteriores a versiones 8.13.6, y desde versiones 8.14.0 versiones anteriores a 8.16.1 permite a atacantes remotos inyectar HTML o JavaScript arbitrario por medio de una vulnerabilidad de tipo cross site scripting (XSS)
Atlassian Jira Server / Data Center version 8.16.0 suffer from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-01-25 CVE Reserved
- 2021-06-07 CVE Published
- 2021-06-28 First Exploit
- 2024-07-27 EPSS Updated
- 2024-10-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50068 | 2021-06-28 | |
http://packetstormsecurity.com/files/163289/Atlassian-Jira-Server-Data-Center-8.16.0-Cross-Site-Scripting.html | 2024-10-17 |
URL | Date | SRC |
---|---|---|
https://jira.atlassian.com/browse/JRASERVER-72392 | 2022-04-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Data Center Search vendor "Atlassian" for product "Data Center" | < 8.5.14 Search vendor "Atlassian" for product "Data Center" and version " < 8.5.14" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Data Center Search vendor "Atlassian" for product "Data Center" | >= 8.6.0 < 8.13.6 Search vendor "Atlassian" for product "Data Center" and version " >= 8.6.0 < 8.13.6" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Data Center Search vendor "Atlassian" for product "Data Center" | >= 8.14.0 < 8.16.1 Search vendor "Atlassian" for product "Data Center" and version " >= 8.14.0 < 8.16.1" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Search vendor "Atlassian" for product "Jira" | < 8.5.14 Search vendor "Atlassian" for product "Jira" and version " < 8.5.14" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Server Search vendor "Atlassian" for product "Jira Server" | >= 8.6.0 < 8.13.6 Search vendor "Atlassian" for product "Jira Server" and version " >= 8.6.0 < 8.13.6" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Server Search vendor "Atlassian" for product "Jira Server" | >= 8.14.0 < 8.16.1 Search vendor "Atlassian" for product "Jira Server" and version " >= 8.14.0 < 8.16.1" | - |
Affected
|