Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-14275

HTTP Header Injection vulnerability: os_destination value not properly escaped when used as redirect location

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.10.2
    • None
    • None

      Issue to track the Seraph security vulnerability, SER-127, and including the fix in Confluence (once it is fixed).

          Form Name

            [CONFSERVER-14275] HTTP Header Injection vulnerability: os_destination value not properly escaped when used as redirect location

            Andrew Lynch (Inactive) added a comment - - edited

            Instructions for installing the patch

            Attached to this JIRA issue is the patched jar file that will correct this problem.

            Simply remove the existing atlassian-seraph-0.38-<version>.jar file from your WEB-INF/lib folder and replace it with the atlassian-seraph-0.38.3.jar file attached to this JIRA issue.

            Note: You will need to restart your application server running Confluence for this patch to take effect.

            This patch should be compatible with Confluence 2.8.2 upwards.

            Regards,
            Andrew Lynch

            Andrew Lynch (Inactive) added a comment - - edited Instructions for installing the patch Attached to this JIRA issue is the patched jar file that will correct this problem. Simply remove the existing atlassian-seraph-0.38-<version>.jar file from your WEB-INF/lib folder and replace it with the atlassian-seraph-0.38.3.jar file attached to this JIRA issue. Note: You will need to restart your application server running Confluence for this patch to take effect. This patch should be compatible with Confluence 2.8.2 upwards. Regards, Andrew Lynch

            Matt Ryall added a comment -

            Andrew, we need a patch (new version of Seraph?) attached here for Confluence versions 2.8.x and 2.9.x.

            Matt Ryall added a comment - Andrew, we need a patch (new version of Seraph?) attached here for Confluence versions 2.8.x and 2.9.x.

            Matt Ryall added a comment -

            We should probably check with JIRA to see if they have an acceptance test we can use to test for this vulnerability in Confluence.

            Matt Ryall added a comment - We should probably check with JIRA to see if they have an acceptance test we can use to test for this vulnerability in Confluence.

              alynch Andrew Lynch (Inactive)
              matt@atlassian.com Matt Ryall
              Affected customers:
              0 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: