Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

XSS vulnerability in jira instance 6.4.9

Mir Sajid ali
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 7, 2020

We identified a XSS (cross site scripting) vulnerability affecting web application. 

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way.

 

Do we have any solution or patch?

 

 

1 answer

1 vote
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
October 7, 2020

I can't see a logged issue for an XSS attack on 6.4.9 specifically, but there are a few for 6.x that you might want to read through to see if there is something you can patch in.

However, the recommended solution/patch for all of those vulnerabilitues is simple - upgrade to a supported version.  The lowest supported version is 7.13, but even that expires in a few weeks and I would strongly recommend that you upgrade to 8.5.8 (the latest "long term support" release), going from 6.4.9 -> 7.0.11 -> 7.13.17 -> 8.5.8

Suggest an answer

Log in or Sign up to answer