• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.8.1
    • 2.8
    • None

      Referrer URLs are not encoded in viewinfo.vm

        1. PageInfoAction.class
          9 kB
        2. viewinfo.vm
          24 kB

            [CONFSERVER-11524] XSS vulnerability in viewinfo.action

            Anatoli added a comment -

            It is possible to remove a referrer under Administration Console - > Manage Referrers by purging referrers with a particular prefix.
            It is also possible not to show referrers in page info by disabling it under Administration Console - > Manage Referrers

            Anatoli added a comment - It is possible to remove a referrer under Administration Console - > Manage Referrers by purging referrers with a particular prefix. It is also possible not to show referrers in page info by disabling it under Administration Console - > Manage Referrers

            Anatoli added a comment -

            Patch Instructions for 2.7.x and 2.8.0 users

            1. Shutdown Confluence
            2. Create the following directories com/atlassian/confluence/pages/actions in your confluence/WEB-INF/classes directory.
            3. Copy the attached PageInfoAction.class to confluence/WEB-INF/classes/com/atlassian/confluence/pages/actions
            4. Copy the attached viewinfo.vm to confluence/pages
            5. Startup Confluence

            Anatoli added a comment - Patch Instructions for 2.7.x and 2.8.0 users Shutdown Confluence Create the following directories com/atlassian/confluence/pages/actions in your confluence/WEB-INF/classes directory. Copy the attached PageInfoAction.class to confluence/WEB-INF/classes/com/atlassian/confluence/pages/actions Copy the attached viewinfo.vm to confluence/pages Startup Confluence

              akazatchkov Anatoli
              Anonymous Anonymous
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: