CVE-2019-3402
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 8.9%
exploitation probability
8.9%top 5% of all CVEs
observed exploitation
nono source reports it
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
Affected products
Atlassian · Jira