Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36801


Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.


Published

2022-08-10T03:15:08.187

Last Modified

2024-11-21T07:13:47.443

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian jira_data_center < 8.20.8 Yes
Application atlassian jira_server < 8.20.8 Yes

References