Atlassian · Jira · CVE-2021-26080
**Name of the Vulnerable Software and Affected Versions**
Jira Server versions prior to 8.5.14
Jira Server versions 8.6.0 through 8.13.6
Jira Server versions 8.14.0 through 8.16.1
Jira Data Center versions prior to 8.5.14
Jira Data Center versions 8.6.0 through 8.13.6
Jira Data Center versions 8.14.0 through 8.16.1
**Description**
The issue allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the EditworkflowScheme.jspa page.
**Recommendations**
For Jira Server versions prior to 8.5.14, update to version 8.5.14 or later.
For Jira Server versions 8.6.0 through 8.13.6, update to version 8.13.6 or later.
For Jira Server versions 8.14.0 through 8.16.1, update to version 8.16.1 or later.
For Jira Data Center versions prior to 8.5.14, update to version 8.5.14 or later.
For Jira Data Center versions 8.6.0 through 8.13.6, update to version 8.13.6 or later.
For Jira Data Center versions 8.14.0 through 8.16.1, update to version 8.16.1 or later.