Uploaded image for project: 'Jira Cloud'
  1. Jira Cloud
  2. JRACLOUD-24532

When entering an excessively long Field Configuration, a system error is produced

    XMLWordPrintable

Details

    Description

      NOTE: This bug report is for JIRA Cloud. Using JIRA Server? See the corresponding bug report.

      Entering a new field configuration with:

      Name:

      <script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script>
      

      Description

      <script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script><script>alert("wtf");</script>
      

      produces:

      Cause: 
      com.atlassian.jira.exception.DataAccessException: Could not load the default FieldLayout
      
      Stack Trace: [hide]
      
      com.atlassian.jira.exception.DataAccessException: Could not load the default FieldLayout
      	at com.atlassian.jira.issue.fields.layout.field.AbstractFieldLayoutManager.storeEditableFieldLayout(AbstractFieldLayoutManager.java:243)
      	at com.atlassian.jira.web.action.admin.issuefields.enterprise.ViewFieldLayouts.doAddFieldLayout(ViewFieldLayouts.java:60)
      	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
      	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
      	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
      	at java.lang.reflect.Method.invoke(Method.java:597)
      	at webwork.util.InjectionUtils$DefaultInjectionImpl.invoke(InjectionUtils.java:70)
      	at webwork.util.InjectionUtils.invoke(InjectionUtils.java:56)
      	at webwork.action.ActionSupport.invokeCommand(ActionSupport.java:433)
      	at webwork.action.ActionSupport.execute(ActionSupport.java:157)
      	at com.atlassian.jira.action.JiraActionSupport.execute(JiraActionSupport.java:75)
      	at webwork.interceptor.DefaultInterceptorChain.proceed(DefaultInterceptorChain.java:39)
      	at webwork.interceptor.NestedInterceptorChain.proceed(NestedInterceptorChain.java:31)
      	at webwork.interceptor.ChainedInterceptor.intercept(ChainedInterceptor.java:16)
      	at webwork.interceptor.DefaultInterceptorChain.proceed(DefaultInterceptorChain.java:35)
      	at webwork.dispatcher.GenericDispatcher.executeAction(GenericDispatcher.java:205)
      	at webwork.dispatcher.GenericDispatcher.executeAction(GenericDispatcher.java:143)
      	at com.atlassian.jira.web.dispatcher.JiraWebworkActionDispatcher.service(JiraWebworkActionDispatcher.java:152)
      	at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
      	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
      	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
      	at com.atlassian.jira.web.filters.steps.ChainedFilterStepRunner.doFilter(ChainedFilterStepRunner.java:74)
      	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
      

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              pslade@atlassian.com sladey
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: