Vulnerability Description
The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira | < 8.8.2 |
| Atlassian | Jira Software Data Center | < 8.8.2 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/JRASERVER-71184Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-71184Issue TrackingVendor Advisory
FAQ
What is CVE-2020-14164?
CVE-2020-14164 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by ...
How severe is CVE-2020-14164?
CVE-2020-14164 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14164?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira, Atlassian Jira Software Data Center.