CVE-2019-20900: Atlassian Jira Data Center

Medium severity, CVSS 4.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.

Affected products

  • Atlassian Jira Data Center: from 8.2.1, before 8.7.0 (fixed in 8.7.0)
  • Atlassian Jira Server: from 8.2.1, before 8.7.0 (fixed in 8.7.0)

Published 2020-07-13. Last modified 2026-06-17.