CVE-2021-43945

Severity
4.8MEDIUM
EPSS
0.2%
top 56.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMar 1

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages4 packages

CVEListV5atlassian/jira_data_centerunspecified8.20.3
CVEListV5atlassian/jira_serverunspecified8.20.3
NVDatlassian/data_center< 8.20.3
NVDatlassian/jira< 8.20.3

🔴Vulnerability Details

2
GHSA
GHSA-p59c-ffj3-xrcm: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or2022-03-01
CVEList
CVE-2021-43945: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or2022-02-28
CVE-2021-43945 (MEDIUM CVSS 4.8) | Affected versions of Atlassian Jira | cvebase.io