• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 3.0-rc1
    • 3.0-beta3
    • None

      If a page is being editted by

      <script>alert('hacked')</script>
      

      and another user edits it at the same time, they are vulnerable to a potential XSS attack.

        1. page-editor-210-patched.js
          24 kB
          Andrew Lynch
        2. page-editor-29-patched.js
          22 kB
          Andrew Lynch

            [CONFSERVER-15883] XSS in concurrent edit notification

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2877948 ] New: CONFSERVER Bug Workflow v4 [ 3004010 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2781980 ] New: JAC Bug Workflow v3 [ 2877948 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2710316 ] New: JAC Bug Workflow v2 [ 2781980 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2375540 ] New: JAC Bug Workflow [ 2710316 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2262239 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2375540 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212289 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2262239 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2159402 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212289 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1944540 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2159402 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1741487 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1944540 ]
            Katherine Yabut made changes -
            Workflow Original: CONF Bug Subtask WF (TEMP) [ 1701879 ] New: Confluence Workflow - Public Facing - Restricted v3 [ 1741487 ]

              cmiller CharlesA
              alynch Andrew Lynch (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: