An unauthenticated XSS vulnerability has been confirmed in confluence 5.8.15 and 5.8.14.

      The vulnerability is located at /rest/prototype/1/session/check/something

      POC URL:
      http://<server>/conf_path/rest/prototype/1/session/check/something%3Cimg%20src%3da%20onerror%3dalert%280%29%3E

      This was confirmed in the latest version of firefox.

            [CONFSERVER-39689] Rest API XSS

            kschoenh: this is fixed in 5.9 as well.

            Chii (Inactive) added a comment - kschoenh : this is fixed in 5.9 as well.

            Question, the fix version only says "5.8.17", which was GA on Nov 19th 2015. Confluence 5.9 was GA on Nov 24th, five days later. Can you confirm CONF-39689/CVE-2015-8398 is fixed in 5.9.x?

            Kelly Schoenhofen added a comment - Question, the fix version only says "5.8.17", which was GA on Nov 19th 2015. Confluence 5.9 was GA on Nov 24th, five days later. Can you confirm CONF-39689 /CVE-2015-8398 is fixed in 5.9.x?

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

            Deleted Account (Inactive) added a comment - This issue is mentioned in release Confluence 6.0.0-OD-2015.50.1-0003 just promoted to jirastudio-prd-virtual

              mtran@atlassian.com Minh Tran
              fa1767dc8cc8 Sebastian Perez
              Affected customers:
              0 This affects my team
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: