CVE-2019-8450
published 2019-09-11CVE-2019-8450: Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have…
PriorityP418medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.88%
54.8th percentile
Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a custom field.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira | >= 8.0.0 < unspecified | unspecified |
| atlassian | jira | >= unspecified < 7.13.6 | 7.13.6 |
| atlassian | jira | >= unspecified < 8.4.0 | 8.4.0 |
| atlassian | jira_server | >= 7.13.0 < 7.13.6 | 7.13.6 |
| atlassian | jira_server | >= 8.0.0 < 8.4.0 | 8.4.0 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wgx3-89qx-v29j: Various templates of the Optimization plugin in Jira before version 7
ghsa_unreviewed·2022-05-24
CVE-2019-8450 [LOW] CWE-79 GHSA-wgx3-89qx-v29j: Various templates of the Optimization plugin in Jira before version 7
Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a custom field.
OSV
squid, squid3 vulnerabilities
osv·2020-02-20·CVSS 7.5
CVE-2019-12528 squid, squid3 vulnerabilities
squid, squid3 vulnerabilities
Jeriko One discovered that Squid incorrectly handled memory when connected
to an FTP server. A remote attacker could possibly use this issue to obtain
sensitive information from Squid memory. (CVE-2019-12528)
Regis Leroy discovered that Squid incorrectly handled certain HTTP
requests. A remote attacker could possibly use this issue to access server
resources prohibited by earlier security filters. (CVE-2020-8449)
Guido Vranken discovered that Squid incorrectly handled certain buffer
operations when acting as a reverse proxy. A remote attacker could use
this issue to cause Squid to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-8450)
Aaron Costello discovered that Squid incorrectly handled certain NTLM
authentication
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-11
Published