Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-13717

Attachment list in popup doesn't escape filenames causing XSS hole

      The filenames in the attachment list of the link popup aren't being escaped.
      If you upload an attachment with a filename including html it could be executed.

            [CONFSERVER-13717] Attachment list in popup doesn't escape filenames causing XSS hole

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2894925 ] New: CONFSERVER Bug Workflow v4 [ 2987305 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2782214 ] New: JAC Bug Workflow v3 [ 2894925 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2710680 ] New: JAC Bug Workflow v2 [ 2782214 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2375996 ] New: JAC Bug Workflow [ 2710680 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2263003 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2375996 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212733 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2263003 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2160429 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212733 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1916340 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2160429 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1721918 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1916340 ]
            Katherine Yabut made changes -
            Workflow Original: CONF Bug Subtask WF (TEMP) [ 1675017 ] New: Confluence Workflow - Public Facing - Restricted v3 [ 1721918 ]

              mjensen m@ (Inactive)
              mjensen m@ (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: