-
Bug
-
Resolution: Fixed
-
Medium
-
6.5.1
-
Severity 2 - Major
-
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
Form Name |
---|
[CONFSERVER-54905] XSS in the viewdefaultdecorator resource through the key parameter - CVE-2017-18085
Fixed in Enterprise Release/s | New: [Download 6.6|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Workflow | Original: JAC Bug Workflow v3 [ 2890114 ] | New: CONFSERVER Bug Workflow v4 [ 2982484 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2803776 ] | New: JAC Bug Workflow v3 [ 2890114 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2737701 ] | New: JAC Bug Workflow v2 [ 2803776 ] |
Symptom Severity | Original: Major [ 14431 ] | New: Severity 2 - Major [ 15831 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2594775 ] | New: JAC Bug Workflow [ 2737701 ] |
Description | Original: The viewdefaultdecorator resource in Atlassian Confluence before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. | New: The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. |
Description | Original: The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. | New: The viewdefaultdecorator resource in Atlassian Confluence before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. |
Description | Original: The viewdefaultdecorator resource in Atlassian Confluence before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. | New: The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. |
Description | Original: The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. | New: The viewdefaultdecorator resource in Atlassian Confluence before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. |