VYPR
Medium severity6.1NVD Advisory· Published Nov 1, 2021· Updated Jun 17, 2026

CVE-2021-41310

CVE-2021-41310

Description

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:atlassian:jira_software_data_center:*:*:*:*:*:*:*:*
    Range: <8.5.19
  • Atlassian/Jira Serverllm-fuzzy2 versions
    <8.5.19, 8.6.0 to <8.13.11, 8.14.0 to <8.19.1+ 1 more
    • (no CPE)range: <8.5.19, 8.6.0 to <8.13.11, 8.14.0 to <8.19.1
    • (no CPE)range: unspecified
  • Atlassian/Jirallm-fuzzy
    Range: <8.5.19, 8.6.0 to <8.13.11, 8.14.0 to <8.19.1
  • Atlassian/Jira Core Data Centerllm-fuzzy2 versions
    <8.5.19, 8.6.0 to <8.13.11, 8.14.0 to <8.19.1+ 1 more
    • (no CPE)range: <8.5.19, 8.6.0 to <8.13.11, 8.14.0 to <8.19.1
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.