We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo default 'internal server error' page.
This issue is reported in our security advisory on this page:
https://confluence.atlassian.com/x/rQP5FQ
You can read more about XSS attacks at:
[BAM-10026] XSS vulnerability in default 'internal server error' page
Workflow | Original: Bamboo Workflow 2016 v1 - Restricted [ 1442878 ] | New: JAC Bug Workflow v3 [ 3383587 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: Bamboo Workflow 2016 v1 [ 1420505 ] | New: Bamboo Workflow 2016 v1 - Restricted [ 1442878 ] |
Workflow | Original: Bamboo Workflow 2014 v2 [ 610374 ] | New: Bamboo Workflow 2016 v1 [ 1420505 ] |
Labels | Original: advisory security | New: advisory cvss-high security |
Workflow | Original: Bamboo Workflow 2014 [ 593043 ] | New: Bamboo Workflow 2014 v2 [ 610374 ] |
Workflow | Original: Bamboo Workflow 2010 [ 351512 ] | New: Bamboo Workflow 2014 [ 593043 ] |
Description |
Original:
We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo default 'internal server error' page.
This issue is reported in our security advisory on this page: http://confluence.atlassian.com/x/lwH6Dw You can read more about XSS attacks at: * http://www.cgisecurity.com/xss-faq.html * http://www.cert.org/advisories/CA-2000-02.html |
New:
We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo default 'internal server error' page.
This issue is reported in our security advisory on this page: https://confluence.atlassian.com/x/rQP5FQ You can read more about XSS attacks at: * http://www.cgisecurity.com/xss-faq.html * http://www.cert.org/advisories/CA-2000-02.html |
Security | Original: Reporters and Developers [ 10070 ] |
Labels | New: advisory security |
Description |
Original:
We have identified and fixed a cross-site scripting (XSS) vulnerability in the Bamboo default 'internal server error' page.
This issue is reported in our security advisory on this page: http://confluence.atlassian.com/x/lwH6Dw You can read more about XSS attacks at: * http://www.cgisecurity.com/xss-faq.html * http://www.cert.org/advisories/CA-2000-02.html |
New:
We have identified and fixed a reflected cross-site scripting (XSS) vulnerability in the Bamboo default 'internal server error' page.
This issue is reported in our security advisory on this page: http://confluence.atlassian.com/x/lwH6Dw You can read more about XSS attacks at: * http://www.cgisecurity.com/xss-faq.html * http://www.cert.org/advisories/CA-2000-02.html |