PT-2020-7188 · Atlassian · Jira+1

Published

2020-02-13

·

Updated

2020-02-24

·

CVE-2012-1500

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions JIRA version 4.4.3 GreenHopper versions prior to 5.9.8
Description The issue allows an attacker to inject arbitrary script code, enabling a Stored XSS attack. This is possible due to a vulnerability in the UpdateFieldJson.jspa file.
Recommendations For JIRA version 4.4.3, update to a version later than 4.4.3 to resolve the issue. For GreenHopper versions prior to 5.9.8, update to version 5.9.8 or later to fix the vulnerability. As a temporary workaround, consider restricting access to the UpdateFieldJson.jspa file until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1500

Affected Products

Greenhopper
Jira