-
Bug
-
Resolution: Fixed
-
Medium
-
6.4.1
-
Severity 2 - Major
-
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
[CONFSERVER-54907] XSS in various resources in the issuesURL parameter - CVE-2017-18086
Workflow | Original: JAC Bug Workflow v3 [ 2890115 ] | New: CONFSERVER Bug Workflow v4 [ 2982485 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2803777 ] | New: JAC Bug Workflow v3 [ 2890115 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2737702 ] | New: JAC Bug Workflow v2 [ 2803777 ] |
Symptom Severity | Original: Major [ 14431 ] | New: Severity 2 - Major [ 15831 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2594781 ] | New: JAC Bug Workflow [ 2737702 ] |
Labels | Original: CVE-2017-18086 advisory advisory-to-release cvss-medium security xss | New: CVE-2017-18086 advisory advisory-released cvss-medium security xss |
Security | Original: Atlassian Staff [ 10750 ] |
Priority | Original: Low [ 4 ] | New: Medium [ 3 ] |
Labels | Original: advisory advisory-to-release cvss-medium security xss | New: CVE-2017-18086 advisory advisory-to-release cvss-medium security xss |
Summary | Original: XSS in various resources through the issuesURL parameter - | New: XSS in various resources in the issuesURL parameter - CVE-2017-18086 |