Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-20109

Link editor displays raw Velocity code after applying security patch

    XMLWordPrintable

Details

    Description

      After applying the patches from 2010-05-04 security advisory, the search box in link editor spits code:

      $generalUtil.escapeXml($!searchQuery.queryString)
      

      To reproduce, just open the link editor while editing a page.

      This is due to the included patch WEB-INF\classes\com\atlassian\confluence\util\GeneralUtil.class

      Problem does not exist in patch for 3.x.

      Attachments

        Activity

          People

            shaffenden Steve Haffenden (Inactive)
            amohdaris Azwandi Mohd Aris (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: