Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-36251

XSS in Pie Chart and Heat Map

XMLWordPrintable

      NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.

      Pie Chart and Heat Map have a persistent XSS vulnerability.

      When HTML tag is stored as Custom Field name (e.g. <script>) then after configuring Pie Chart (or Heat Map) and pressing Save the gadget is not shown but stays at configuration state.

      Only after refreshing the gadget displays information.

        1. PieChart.png
          34 kB
          Ignat
        2. xss.png
          157 kB
          Ignat

            ohernandez@atlassian.com Oswaldo Hernandez (Inactive)
            ialexeyenko Ignat (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: