CVE-2019-20900: Atlassian Jira Data Center
Medium severity, CVSS 4.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.
Affected products
- Atlassian Jira Data Center: from 8.2.1, before 8.7.0 (fixed in 8.7.0)
- Atlassian Jira Server: from 8.2.1, before 8.7.0 (fixed in 8.7.0)
Published 2020-07-13. Last modified 2026-06-17.