• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 1.1.2
    • 1.1
    • None

      We have identified and fixed a persistent cross-site scripting (XSS) vulnerabilities that affects Stash instances, including publicly available instances (that is, Internet-facing servers). XSS vulnerabilities allow an attacker to embed their own JavaScript into a Stash page.

      More information is available in advisory at https://confluence.atlassian.com/display/STASH/Stash+security+advisory+2012-09-04

            [BSERV-2676] Persistent Cross Site Scripting Vulnerability

            Rachel Robins made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 284765 ]
            Owen made changes -
            Workflow Original: Stash Workflow - Restricted [ 1447414 ] New: JAC Bug Workflow v3 [ 3136791 ]
            Rachel Robins made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 274009 ]
            Paz (Inactive) made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 284765 ] New: This issue links to "Page (Atlassian Documentation)" [ 284765 ]
            Paz (Inactive) made changes -
            Remote Link New: This issue links to "Page (Atlassian Documentation)" [ 284765 ]
            Rachel Robins made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 274009 ] New: This issue links to "Page (Atlassian Documentation)" [ 274009 ]
            Rachel Robins made changes -
            Remote Link New: This issue links to "Page (Atlassian Documentation)" [ 274009 ]
            Paz (Inactive) made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 261624 ] New: This issue links to "Page (Atlassian Documentation)" [ 261624 ]
            Paz (Inactive) made changes -
            Remote Link New: This issue links to "Page (Atlassian Documentation)" [ 261624 ]
            Paz (Inactive) made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 252547 ] New: This issue links to "Page (Atlassian Documentation)" [ 252547 ]

              vosipov VitalyA
              vosipov VitalyA
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: