Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-11040

Grouppicker and Userpicker display unescaped user-entered content

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.7.3, 2.8
    • 2.1.5, 2.2.10, 2.3.3, 2.4.5, 2.5.8, 2.6.2, 2.7.2
    • None
    • Browser: MSIE

      As reported at CONF-9559 the spaces/openuserpicker.action and spaces/grouppicker.action display unescaped content that can be entered in the url. This forms an XSS vulnerability.

            [CONFSERVER-11040] Grouppicker and Userpicker display unescaped user-entered content

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2881917 ] New: CONFSERVER Bug Workflow v4 [ 2990553 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2783256 ] New: JAC Bug Workflow v3 [ 2881917 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2708754 ] New: JAC Bug Workflow v2 [ 2783256 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2373593 ] New: JAC Bug Workflow [ 2708754 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2258675 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2373593 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2209650 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2258675 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2155405 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2209650 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1910864 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2155405 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1718208 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1910864 ]
            Katherine Yabut made changes -
            Workflow Original: CONF Bug Subtask WF (TEMP) [ 1669794 ] New: Confluence Workflow - Public Facing - Restricted v3 [ 1718208 ]

              dave@atlassian.com dave (Inactive)
              don.willis@atlassian.com Don Willis
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: