Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-54395

XSS through various RSS properties in the RSS macro - CVE-2017-16856

      The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.

      Acknowledgements

      Atlassian would like to credit Glenn 'devalias' Grant (http://devalias.net) of TSS (https://dtss.com.au) for reporting this issue to us.

            [CONFSERVER-54395] XSS through various RSS properties in the RSS macro - CVE-2017-16856

            Sure. You can disable the macro.

            David Black added a comment - Sure. You can disable the macro.

            Pavel Boev added a comment -

            Is there a temporary workaround that we can apply until we plan the upgrade?

            Like disabling this macro?

            Pavel Boev added a comment - Is there a temporary workaround that we can apply until we plan the upgrade? Like disabling this macro?

            Not at this point in time.

            David Black added a comment - Not at this point in time.

            Can you publish information how to reproduce this issue?

            Deleted Account (Inactive) added a comment - Can you publish information how to reproduce this issue?

            Hi Henri,
            That page discloses critical security issue advisories. This is not a critical security issue so it will not be added to that page.

            David Black added a comment - Hi Henri, That page discloses critical security issue advisories. This is not a critical security issue so it will not be added to that page.

            Is there a regular security advisory about this case? At least I can't see this listed in https://confluence.atlassian.com/doc/confluence-security-overview-and-advisories-134526.html

            Deleted Account (Inactive) added a comment - Is there a regular security advisory about this case? At least I can't see this listed in https://confluence.atlassian.com/doc/confluence-security-overview-and-advisories-134526.html

            Confluence 6.4.1 was the version this issue was reproduced in but earlier versions of Confluence, such as 6.3 are also affected.

            David Black added a comment - Confluence 6.4.1 was the version this issue was reproduced in but earlier versions of Confluence, such as 6.3 are also affected.

            " in Atlassian Confluence before version 6.5.2" yet the issues Affected Version points only for Confluence 6.4. Is Confluence 6.3 affected?

            Ireneusz Lepel added a comment - " in Atlassian Confluence before version 6.5.2" yet the issues Affected Version points only for Confluence 6.4. Is Confluence 6.3 affected?

            Are 5.10 versions affected?

            Deleted Account (Inactive) added a comment - Are 5.10 versions affected?

            This is an independent assessment and you should evaluate its applicability to your own IT environment.
            CVSS v3 score: 5.4 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction Required

            Scope Metric

            Scope Changed

            Impact Metrics

            Confidentiality Low
            Integrity Low
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

            Security Metrics Bot added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 5.4 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction Required Scope Metric Scope Changed Impact Metrics Confidentiality Low Integrity Low Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: