Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-22529

HTML file type attachments are automatically rendered in IE.

    • Icon: Bug Bug
    • Resolution: Obsolete
    • Icon: Medium Medium
    • None
    • 3.5
    • None
    • Internet Explorer with Confluence.

      Steps to reproduce

      1. Create following HTML file and upload to any of Confluence page.
        <script>
        alert("Cookie: " + document.cookie);
        </script>
        
      2. Open the file on Internet Explorer 7.
      3. Then, you will see the javascript in that HTML file executed automatically.

      Issue happens with IE9,8,7 with Confluence 3.5.

      Firefox and Safari presents a download 'save as' dialogue box and does not render.

            [CONFSERVER-22529] HTML file type attachments are automatically rendered in IE.

            Anatoli added a comment -

            No longer applicable, tested against IE8 and IE9

            Anatoli added a comment - No longer applicable, tested against IE8 and IE9

            CVSS score: 6.0 => High severity

            Exploitability Metrics

            AccessVector Network
            AccessComplexity Low
            Authentication Single Instance

            Impact Metrics

            ConfImpact Partial
            IntegImpact Partial
            AvailImpact Partial

            See https://extranet.atlassian.com/display/SECCOUNCIL/How+to+evaluate+vulnerability+severity+under+CVSS for details and http://nvd.nist.gov/cvss.cfm?calculator&adv&version=2 for score calculator.

            David Black added a comment - CVSS score: 6.0 => High severity Exploitability Metrics AccessVector Network AccessComplexity Low Authentication Single Instance Impact Metrics ConfImpact Partial IntegImpact Partial AvailImpact Partial See https://extranet.atlassian.com/display/SECCOUNCIL/How+to+evaluate+vulnerability+severity+under+CVSS for details and http://nvd.nist.gov/cvss.cfm?calculator&adv&version=2 for score calculator.

            This one should have been fixed by my fix for CONF-22132, which is in 3.5.7, but we need to double check.

            Richard Atkins added a comment - This one should have been fixed by my fix for CONF-22132, which is in 3.5.7, but we need to double check.

              Unassigned Unassigned
              vchoy Vincent Choy (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: