-
Bug
-
Resolution: Fixed
-
Highest
-
3.0.2
Upload an image to a page, and include the following in the attachment comment:
<script>alert('vulnerable')</script>
Now display the image using the gallery macro. When the full-size picture is viewed, the script in the comment will be executed.
See example here: https://qa-cac.atlassian.com/display/~mhrynczak/xss+in+gallery
Confluence Administrators — fixing this vulnerability:
Version 1.6.2.11 of Confluence's 'Advanced Macros' plugin contains this fix. (For more information, please refer to: https://plugins.atlassian.com/plugin/details/145).
Version 1.6.2.11 of this plugin is compatible with versions of Confluence back to 3.0.0. Hence, to fix this vulnerability, please upgrade the version of this plugin in your Confluence installation, to at least 1.6.2.11.
To do this, go the 'Atlassian Plugin Repository' in your Confluence Administration console area and upgrade the 'Advanced Macros' plugin to version 1.6.2.11 (or greater).