Issue Details (XML | Word | Printable)

Key: CONF-11524
Type: Bug Bug
Status: Resolved Resolved
Resolution: Fixed
Priority: Major Major
Assignee: Anatoli Kazatchkov [Atlassian]
Reporter: Anonymous
Votes: 0
Watchers: 0
Operations

Add/Edit UI Mockup to this issue
If you were logged in you would be able to see more operations.
Confluence

XSS vulnerability in viewinfo.action

Created: 21/Apr/08 11:28 AM   Updated: 05/Jun/08 07:34 PM
Component/s: Security
Affects Version/s: 2.8
Fix Version/s: 2.8.1

Time Tracking:
Not Specified

File Attachments: 1. Text File PageInfoAction.class (9 kB)
2. File viewinfo.vm (24 kB)

Issue Links:
Cause
 

Participants: Anatoli Kazatchkov [Atlassian], Chris Broadfoot [Atlassian] and Don Willis [Atlassian]
Since last comment: 29 weeks, 4 days ago
Resolution Date: 01/May/08 09:16 PM
Labels:


 Description  « Hide
Referrer URLs are not encoded in viewinfo.vm

 All   Comments   Work Log   Change History      Sort Order: Ascending order - Click to sort in descending order
Anatoli Kazatchkov [Atlassian] added a comment - 04/May/08 08:38 PM

Patch Instructions for 2.7.x and 2.8.0 users

  1. Shutdown Confluence
  2. Create the following directories com/atlassian/confluence/pages/actions in your confluence/WEB-INF/classes directory.
  3. Copy the attached PageInfoAction.class to confluence/WEB-INF/classes/com/atlassian/confluence/pages/actions
  4. Copy the attached viewinfo.vm to confluence/pages
  5. Startup Confluence

Anatoli Kazatchkov [Atlassian] added a comment - 08/May/08 11:32 PM
It is possible to remove a referrer under Administration Console - > Manage Referrers by purging referrers with a particular prefix.
It is also possible not to show referrers in page info by disabling it under Administration Console - > Manage Referrers