-
Bug
-
Resolution: Fixed
-
Medium
-
2.8, 2.8.1, 2.8.2, 2.9, 2.9.1, 2.9.2
After listening to Chris' security talk yesterday, I played around with areas of Confluence I am familiar with and I found a vulnerability in the attachments macro. You can create an attachment name with <script> tags and run script on a page that displays the attachment macro. The Attachments screen doesn't have this vulnerability.
[CONFSERVER-13713] Attachments macro has XSS vulnerability
Workflow | Original: JAC Bug Workflow v3 [ 2891698 ] | New: CONFSERVER Bug Workflow v4 [ 2983748 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2797745 ] | New: JAC Bug Workflow v3 [ 2891698 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2727892 ] | New: JAC Bug Workflow v2 [ 2797745 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2392734 ] | New: JAC Bug Workflow [ 2727892 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 2288555 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2392734 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2227313 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 2288555 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2182767 ] | New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2227313 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 1950963 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2182767 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v3 [ 1744649 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 1950963 ] |
Workflow | Original: CONF Bug Subtask WF (TEMP) [ 1706394 ] | New: Confluence Workflow - Public Facing - Restricted v3 [ 1744649 ] |