When using the CQLSearchService the response returned is inconsistently escaped. If using the highlight strategy, the body content is escaped and the title is not.

      In addition, the actual characters escaped is inconsistent, For example, & lt; should be escaped to & amp;lt; but isn't, while < is correctly escaped to & lt;.

      This seems like it would result in an XSS issue, but it appears to be ok in Confluence search.

            [CONFSERVER-43341] Inconsistent escaping returned by Confluence Search

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2901697 ] New: CONFSERVER Bug Workflow v4 [ 2996276 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2798124 ] New: JAC Bug Workflow v3 [ 2901697 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2723093 ] New: JAC Bug Workflow v2 [ 2798124 ]
            Owen made changes -
            Symptom Severity Original: Minor [ 14432 ] New: Severity 3 - Minor [ 15832 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2386159 ] New: JAC Bug Workflow [ 2723093 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2283128 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2386159 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2223721 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2283128 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2177030 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2223721 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1941908 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2177030 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1739450 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1941908 ]

              mtran@atlassian.com Minh Tran
              zwang@atlassian.com Ziming Wang
              Affected customers:
              0 This affects my team
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: