Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-10542

Request parameters are not HTML encoded on the 500 page

      The 500 page in JIRA lists the request parameters, but does not HTML encode them. This can lead to cross site scripting.

            [JRASERVER-10542] Request parameters are not HTML encoded on the 500 page

            This was reported on Secunia and has since been resolved. This XSS iss ue is no longer an issue.

            Cheers,
            Nick

            Nick Menere [Atlassian] (Inactive) added a comment - This was reported on Secunia and has since been resolved. This XSS iss ue is no longer an issue. Cheers, Nick

            html encoded the request parameters on the 500 page

            Sam Chang [Atlassian] added a comment - html encoded the request parameters on the 500 page

              sam@atlassian.com Sam Chang [Atlassian]
              anton@atlassian.com AntonA
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: