We are using below versions of JIRA.
- Jira Server - 8.21
- Jira service management - 4.21.0
- Adaptavist ScriptRunner - 6.41.0
- JEMH -3.3.71
- JSU Automation Suite -2.32
- Atlassian Universal Plugin Manager - 5.1.2
And we are getting below vulnerable issue when we do the VA scan. Anyone know how to solve this issue and which plugin has this js file?
siteurl/c277de0b4cdbabf116059d3b0bf2ca75-CDN/-h2lxxw/821000/1vdrktf/d2e244e05c844200cbfd78d4cbb94e58/_/download/contextbatch/js/_super/factories/backbone/1.0.0/backbone-1.0.0-factory.js)
* Line 33:Unsafe client output calling this.location.replace() with tainted arg
* Line 33:String concatenation with user-controlled value
* Line 33:String concatenation with user-controlled value
* Line 33:String concatenation with user-controlled value
* Line 33:"this.location.search" is controlled by the user