漏洞描述 版本7.6.6之前的Atlassian JiraConfluence、版本7.7.4之前的版本7.7.0、版本7.8.4之前的7.8.0以及版本7.9.2之前的7.9.0,允许远程攻击者在指定无效值时,通过自定义字段的错误消息中的跨站点脚本漏洞注入任意HTML或JavaScript。
相关漏洞推荐 POC CVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery POC CVE-2018-20824: Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting POC CVE-2018-5230: Atlassian Jira Confluence - Cross-Site Scripting POC CVE-2019-11581: Atlassian Jira Server-Side Template Injection POC CVE-2019-3401: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization POC CVE-2020-14179: Atlassian Jira Server/Data Center <8.5.8/8.6.0 - 8.11.1 - Information Disclosure POC CVE-2021-26086: Atlassian Jira Limited - Local File Inclusion POC CVE-2022-0540: Atlassian Jira Seraph - Authentication Bypass POC CVE-2019-11581: Atlassian Jira未授权服务端模板注入漏洞 POC CVE-2019-8442: Atlassian Jira webroot leak POC jira-setup: Atlassian JIRA Setup - Installer Atlassian Jira Mobile 插件 SSRF 漏洞 Atlassian Jira CVE-2022-0540认证绕过漏洞