Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-54907

XSS in various resources in the issuesURL parameter - CVE-2017-18086

      Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.

            [CONFSERVER-54907] XSS in various resources in the issuesURL parameter - CVE-2017-18086

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2890115 ] New: CONFSERVER Bug Workflow v4 [ 2982485 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2803777 ] New: JAC Bug Workflow v3 [ 2890115 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2737702 ] New: JAC Bug Workflow v2 [ 2803777 ]
            Owen made changes -
            Symptom Severity Original: Major [ 14431 ] New: Severity 2 - Major [ 15831 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2594781 ] New: JAC Bug Workflow [ 2737702 ]
            David Black made changes -
            Labels Original: CVE-2017-18086 advisory advisory-to-release cvss-medium security xss New: CVE-2017-18086 advisory advisory-released cvss-medium security xss
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release cvss-medium security xss New: CVE-2017-18086 advisory advisory-to-release cvss-medium security xss
            David Black made changes -
            Summary Original: XSS in various resources through the issuesURL parameter - New: XSS in various resources in the issuesURL parameter - CVE-2017-18086

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: