Cross-site scripting in Jira Software - CVE-2020-4021
Published: June 1, 2020 / Updated: July 17, 2020
Jira Software
Atlassian
Description
The vulnerability allows a remote authenticated user to read and manipulate data.
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.