Vulnerability Details CVE-2021-43943
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.8%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2021-43943
-
cpe:2.3:a:atlassian:jira_service_management:4.0.0
-
cpe:2.3:a:atlassian:jira_service_management:4.13.22
-
cpe:2.3:a:atlassian:jira_service_management:4.14.0
-
cpe:2.3:a:atlassian:jira_service_management:4.14.1
-
cpe:2.3:a:atlassian:jira_service_management:4.15.0
-
cpe:2.3:a:atlassian:jira_service_management:4.15.1
-
cpe:2.3:a:atlassian:jira_service_management:4.16.0
-
cpe:2.3:a:atlassian:jira_service_management:4.16.1
-
cpe:2.3:a:atlassian:jira_service_management:4.16.2
-
cpe:2.3:a:atlassian:jira_service_management:4.17.0
-
cpe:2.3:a:atlassian:jira_service_management:4.17.1
-
cpe:2.3:a:atlassian:jira_service_management:4.18.0
-
cpe:2.3:a:atlassian:jira_service_management:4.18.1
-
cpe:2.3:a:atlassian:jira_service_management:4.18.2
-
cpe:2.3:a:atlassian:jira_service_management:4.19.0
-
cpe:2.3:a:atlassian:jira_service_management:4.19.1
-
cpe:2.3:a:atlassian:jira_service_management:4.20.0
-
cpe:2.3:a:atlassian:jira_service_management:4.20.1
-
cpe:2.3:a:atlassian:jira_service_management:4.20.10
-
cpe:2.3:a:atlassian:jira_service_management:4.20.11
-
cpe:2.3:a:atlassian:jira_service_management:4.20.12
-
cpe:2.3:a:atlassian:jira_service_management:4.20.13
-
cpe:2.3:a:atlassian:jira_service_management:4.20.14
-
cpe:2.3:a:atlassian:jira_service_management:4.20.15
-
cpe:2.3:a:atlassian:jira_service_management:4.20.16
-
cpe:2.3:a:atlassian:jira_service_management:4.20.17
-
cpe:2.3:a:atlassian:jira_service_management:4.20.18
-
cpe:2.3:a:atlassian:jira_service_management:4.20.19
-
cpe:2.3:a:atlassian:jira_service_management:4.20.2
-
cpe:2.3:a:atlassian:jira_service_management:4.20.20
-
cpe:2.3:a:atlassian:jira_service_management:4.20.21
-
cpe:2.3:a:atlassian:jira_service_management:4.20.22
-
cpe:2.3:a:atlassian:jira_service_management:4.20.23
-
cpe:2.3:a:atlassian:jira_service_management:4.20.24
-
cpe:2.3:a:atlassian:jira_service_management:4.20.25
-
cpe:2.3:a:atlassian:jira_service_management:4.20.26
-
cpe:2.3:a:atlassian:jira_service_management:4.20.3
-
cpe:2.3:a:atlassian:jira_service_management:4.20.4
-
cpe:2.3:a:atlassian:jira_service_management:4.20.5
-
cpe:2.3:a:atlassian:jira_service_management:4.20.6
-
cpe:2.3:a:atlassian:jira_service_management:4.20.7
-
cpe:2.3:a:atlassian:jira_service_management:4.20.8
-
cpe:2.3:a:atlassian:jira_service_management:4.20.9