Jira - Reflected XSS using searchOwnerUserName parameter.

Published on 10 Jan 2022
Vulnerability

Description

Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 is vulnerable to Reflected cross-site scripting (XSS) in ConfigurePortalPages.jspa it allows remote attackers to inject arbitrary HTML or JavaScript searchOwnerUserName parameter.

Recommendation

  • Update to the latest version
Jijith Rajan
Written by
Cyber Security Engineer

His passion for staying abreast of the latest security threats and trends, coupled with his hands-on experience, allows him to actively contribute to the protection of digital assets. Jijith's dedication and enthusiasm make him a promising talent in the ever-evolving realm of cybersecurity, promising a safer digital future.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo