← back
CVE-2019-3402

CVE-2019-3402

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 8.9%
exploitation probability
8.9%top 5% of all CVEs
observed exploitation
nono source reports it
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
Affected products
Atlassian · Jira