Description
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
In plain language
AI Worth attentionCVE-2019-3402 is a web-page weakness in older Atlassian Jira that can let an attacker add harmful scripts to someone else’s browser using a crafted link; most small businesses should fix it if they’re running an affected Jira version.
CVE-2019-3402 is a cross-site scripting (XSS) flaw in Jira’s ConfigurePortalPages.jspa that allows remote attackers to inject arbitrary HTML/JavaScript by manipulating the user name search parameter, with no login required but requiring a victim to open a crafted link.
What to do now
- Check your Atlassian Jira version and confirm it is either before 7.13.3, or between 8.0.0 and 8.1.1.
- If you are on a vulnerable version, plan an upgrade to the fixed release.
- Upgrade Jira so it is fixed: use 7.13.3 for Jira, and 8.1.1 for Jira Server.
- After upgrading, test that portal page functionality (including user name search) still works as expected and that the deployed version matches the fixed target.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-3402 and every CVE in our database. Create a free account — no credit card required.
Create Free Account