RULE(RULE ID:333349)

Rule General Information
Release Date: 2021-03-30
Rule Name: Jira Labels Gadget XSS Vulnerability (CVE-2019-3400)
Severity:
CVE ID:
Rule Protection Details
Description: The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:108168
https://jira.atlassian.com/browse/JRASERVER-69245
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://jira.atlassian.com/browse/JRASERVER-69245