S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-3402 Scanner

CVE-2019-3402 scanner - Cross-Site Scripting (XSS) vulnerability in Atlassian Jira

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-3402
6.1
CVSS

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jiraby Atlassian
AFFECTED< 7.13.3SAFE ✓≥ 7.13.3
Updated Aug 21, 2026View on NVD →
Detail

Atlassian Jira is a software used for project management and issue tracking. It is widely popular in the software development industry due to its ability to help teams collaborate, plan, and release software quickly. With Jira, teams can organize work, assign tasks, track time, and resolve issues all in one place. The software also comes with a range of customizable workflows and dashboards that allow teams to tailor the software to their specific project needs. Overall, Atlassian Jira is an essential tool for software development teams looking to improve their productivity and streamline their workflow.

One of the vulnerabilities identified in Atlassian Jira is the CVE-2019-3402. This vulnerability exists in the ConfigurePortalPages.jspa resource and is present in versions 7.13.3 and from 8.0.0 to 8.1.1. This vulnerability is caused by an issue with cross-site scripting (XSS) where an attacker can inject arbitrary HTML or JavaScript through the searchOwnerUserName parameter. This allows the attacker to execute malicious code on the client-side, bypass authentication, or steal sensitive information.

If exploited, the CVE-2019-3402 vulnerability in Atlassian Jira can lead to several issues. Firstly, it can result in unauthorized access to sensitive information, which can lead to data breaches. Secondly, it can allow an attacker to manipulate the software interface, redirect users to malicious websites, or execute malicious code on the client-side. This could result in the compromise of the entire system, loss of important data, and reputational damage to the organization.

With the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive vulnerability assessment and management solution for applications, websites, and infrastructure. The platform's features include vulnerability scanning, asset discovery, automated testing, and unified reporting. By leveraging its pro features, s4e.io can help organizations identify and remediate vulnerabilities in their systems before they are exploited by attackers, protecting against data breaches and reputational damage.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is essential to apply the following precautions:

  • Keep the Atlassian Jira software updated to the latest version.
  • Configure security settings to limit access to sensitive information and restrict user permissions.
  • Implement content security policies (CSP) to prevent malicious code execution.
  • Regularly scan the system for vulnerabilities and apply security patches promptly.
  • Use security tools like firewalls, antivirus software, and intrusion detection systems to monitor and prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-3402 scanner - Cross-Site Scripting (XSS) vulnerability in Atlassian Jira | S4E