Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-14275

HTTP Header Injection vulnerability: os_destination value not properly escaped when used as redirect location

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.10.2
    • None
    • None

      Issue to track the Seraph security vulnerability, SER-127, and including the fix in Confluence (once it is fixed).

            [CONFSERVER-14275] HTTP Header Injection vulnerability: os_destination value not properly escaped when used as redirect location

            IT Team made changes -
            Comment [ we are using {*}atlassian-seraph-4.0.4.jar{*}. So we also need to replace it with 0.38.3 because we are already with the latest version. ]
            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2875985 ] New: CONFSERVER Bug Workflow v4 [ 2981926 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2775808 ] New: JAC Bug Workflow v3 [ 2875985 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2711400 ] New: JAC Bug Workflow v2 [ 2775808 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376856 ] New: JAC Bug Workflow [ 2711400 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2264673 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376856 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2213520 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2264673 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2162323 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2213520 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1918587 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2162323 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1723138 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1918587 ]

              alynch Andrew Lynch (Inactive)
              matt@atlassian.com Matt Ryall
              Affected customers:
              0 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: