An unauthenticated XSS vulnerability has been confirmed in confluence 5.8.15 and 5.8.14.

      The vulnerability is located at /rest/prototype/1/session/check/something

      POC URL:
      http://<server>/conf_path/rest/prototype/1/session/check/something%3Cimg%20src%3da%20onerror%3dalert%280%29%3E

      This was confirmed in the latest version of firefox.

            [CONFSERVER-39689] Rest API XSS

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2891072 ] New: CONFSERVER Bug Workflow v4 [ 2983211 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2781772 ] New: JAC Bug Workflow v3 [ 2891072 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2728075 ] New: JAC Bug Workflow v2 [ 2781772 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2386305 ] New: JAC Bug Workflow [ 2728075 ]
            Minh Tran made changes -
            Fix Version/s New: 5.9.1 [ 55895 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2283405 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2386305 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2223916 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2283405 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2177342 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2223916 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1942474 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2177342 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1739905 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1942474 ]

              mtran@atlassian.com Minh Tran
              fa1767dc8cc8 Sebastian Perez
              Affected customers:
              0 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: