Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-17361

XSS vulnerability can be exploited using the Gallery macro

      Upload an image to a page, and include the following in the attachment comment:

      <script>alert('vulnerable')</script>

      Now display the image using the gallery macro. When the full-size picture is viewed, the script in the comment will be executed.

      See example here: https://qa-cac.atlassian.com/display/~mhrynczak/xss+in+gallery

            [CONFSERVER-17361] XSS vulnerability can be exploited using the Gallery macro

            Confluence Administrators — fixing this vulnerability:

            Version 1.6.2.11 of Confluence's 'Advanced Macros' plugin contains this fix. (For more information, please refer to: https://plugins.atlassian.com/plugin/details/145).

            Version 1.6.2.11 of this plugin is compatible with versions of Confluence back to 3.0.0. Hence, to fix this vulnerability, please upgrade the version of this plugin in your Confluence installation, to at least 1.6.2.11.

            To do this, go the 'Atlassian Plugin Repository' in your Confluence Administration console area and upgrade the 'Advanced Macros' plugin to version 1.6.2.11 (or greater).

            Giles Gaskell [Atlassian] added a comment - Confluence Administrators — fixing this vulnerability: Version 1.6.2.11 of Confluence's 'Advanced Macros' plugin contains this fix. (For more information, please refer to: https://plugins.atlassian.com/plugin/details/145 ). Version 1.6.2.11 of this plugin is compatible with versions of Confluence back to 3.0.0. Hence, to fix this vulnerability, please upgrade the version of this plugin in your Confluence installation, to at least 1.6.2.11. To do this, go the 'Atlassian Plugin Repository' in your Confluence Administration console area and upgrade the 'Advanced Macros' plugin to version 1.6.2.11 (or greater).

            Anatoli added a comment -

            The version of the macro that is compatible with confluence 3.0.x is available here

            Anatoli added a comment - The version of the macro that is compatible with confluence 3.0.x is available here

            Anatoli added a comment -

            The new version of the advanced macros plugin that fixes this problem has been released and is now bundled with confluence 3.1. We will release the version of the plugin that is compatible with confluence 3.0.x.

            Anatoli added a comment - The new version of the advanced macros plugin that fixes this problem has been released and is now bundled with confluence 3.1. We will release the version of the plugin that is compatible with confluence 3.0.x.

            Anatoli added a comment -

            corresponding issue in the plugin's project: https://developer.atlassian.com/jira/browse/ADVMACROS-140

            Anatoli added a comment - corresponding issue in the plugin's project: https://developer.atlassian.com/jira/browse/ADVMACROS-140

            Mark, I hate it when you spoil my evening....

            Per Fragemann [Atlassian] added a comment - Mark, I hate it when you spoil my evening....

              akazatchkov Anatoli
              mhrynczak Mark Hrynczak (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: