Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-19990

The versions of jQuery and jQuery UI in use are vulnerable to several issues

      Similar to JRASERVER-43422, the version of jQuery used (currently version 1.10.2) is vulnerable to jQuery issue 2432 (3rd party $.get() auto executes if content type is text/javascript) and 11974 (parseHTML executes inline scripts like event handlers). Additionally, the version of jQuery UI in use (1.8.24) is vulnerable to CVE-2010-5312 and an attacker can exploit this issue if they are able to provide values to "title" of a jQuery ui dialogue. Actual exploitation / impact to Bamboo depends upon if & how the vulnerable code paths are used.

      On a related note, http://research.insecurelabs.org/jquery/test/ can be used to check jQuery versions for issues.

            [BAM-19990] The versions of jQuery and jQuery UI in use are vulnerable to several issues

            Alexey Chystoprudov made changes -
            Link New: This issue depended on by BAM-21798 [ BAM-21798 ]
            Marcin Walerianczyk made changes -
            Fix Version/s New: 6.10.2 [ 89592 ]
            Fix Version/s Original: 6.10.0 [ 86205 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Bamboo Workflow 2016 v1 - Restricted [ 2745853 ] New: JAC Bug Workflow v3 [ 3386125 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Marcin Oles made changes -
            Fix Version/s New: 6.10.0 [ 86205 ]
            Resolution New: Fixed [ 1 ]
            Status Original: In Progress [ 3 ] New: Resolved [ 5 ]
            Alexey Chystoprudov made changes -
            Remote Link New: This issue links to "UPM-6007 (Ecosystem JIRA)" [ 436694 ]
            Alexey Chystoprudov made changes -
            Assignee Original: Pawel Skierczynski [ pskierczynski ] New: Victor Debone [ vdebone ]
            Pawel Skierczynski made changes -
            Status Original: Open [ 1 ] New: In Progress [ 3 ]
            Pawel Skierczynski made changes -
            Assignee New: Pawel Skierczynski [ pskierczynski ]
            Krystian Brazulewicz made changes -
            Comment [ test mention: [~vdebone] ]
            Victor Debone made changes -
            Remote Link New: This issue links to "BDEV-15347 (Hello Jira)" [ 425537 ]

              vdebone Victor Debone
              dblack David Black
              Affected customers:
              0 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: