Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-11027

XSS vulnerabilities in create/edit/copy page and blogpost actions

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.7.3
    • 2.1.5, 2.2.10, 2.3.3, 2.4.5, 2.5.8, 2.6.2, 2.7.2
    • None

      The following create/edit page URL's are vulnerable:

      • /pages/createpage.action
      • /pages/docreatepage.action
      • /pages/editpage.action
      • /pages/doeditepage.action

      on parentPageString, mode, labelsString, captchaId

      The following create/edit blogpost URL's are vulnerable:

      • /pages/createblogpost.action
      • /pages/docreateblogpost.action
      • /pages/editblogpost.action
      • /pages/doeditblogpost.action

      on mode, labelsString, title, captchaId

      The following copy page URL's are vulnerable:

      • /pages/copypage.action
      • /pages/docopypage.action

      on parentPageString, mode, labelsString, captchaId

      The following comment action URL's are vulnerable:

      • pages/addcomment.action
      • pages/doaddcomment.action

      on mode and captchaId

        1. createblogpost-form.vm
          3 kB
        2. macros.vm
          123 kB
        3. page-labels-form.vm
          3 kB
        4. page-location-form.vm
          4 kB
        5. wiki-textarea.vm
          27 kB

            [CONFSERVER-11027] XSS vulnerabilities in create/edit/copy page and blogpost actions

            Patch instructions for Confluence 2.6.x

            1. Shutdown Confluence
            2. Copy createblogpost-form.vm to confluence/pages/includes
            3. Copy page-labels-form.vm to confluence/pages/includes
            4. Copy page-location-form.vm to confluence/pages/includes
            5. Copy macros.vm to confluence/template/includes
            6. Copy wiki-textarea.vm to confluence/template/notable
            7. Startup Confluence

            Note: These patch files will override the existing files.

            Chris Broadfoot [Atlassian] added a comment - - edited Patch instructions for Confluence 2.6.x Shutdown Confluence Copy createblogpost-form.vm to confluence/pages/includes Copy page-labels-form.vm to confluence/pages/includes Copy page-location-form.vm to confluence/pages/includes Copy macros.vm to confluence/template/includes Copy wiki-textarea.vm to confluence/template/notable Startup Confluence Note: These patch files will override the existing files.

              cbroadfoot Chris Broadfoot [Atlassian]
              dave@atlassian.com dave (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: