-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
7.4.4, 7.9.0
-
None
-
5.4
-
Medium
-
CVE-2020-29444
Affected versions of Team Calendar in Confluence Server allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting vulnerability in admin global setting parameters.
Affected versions:
- < 7.11.0
Fixed version:
- 7.11.0
This vulnerability is attributed to Stefano Castilletti, a security researcher from Apple.
- mentioned in
-
Page Loading...
[CONFSERVER-61266] Persistent XSS through Team Calendar in Confluence Server - CVE-2020-29444
Remote Link | New: This issue links to "Page (Confluence)" [ 733522 ] |
CVE ID | New: CVE-2020-29444 |
Fix Version/s | New: TC-7.0.7 [ 94708 ] | |
Fix Version/s | New: TC-6.1.8 [ 94794 ] |
Affects Version/s | New: 7.4.4 [ 92310 ] |
Labels | Original: CVE-2020-29444 advisory advisory-to-release dont-import security | New: CVE-2020-29444 advisory advisory-released dont-import security |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Security | New: Atlassian Staff [ 10750 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Labels | Original: advisory advisory-to-release dont-import security | New: CVE-2020-29444 advisory advisory-to-release dont-import security |
Summary | Original: Persistent XSS through Team Calendar in Confluence Server | New: Persistent XSS through Team Calendar in Confluence Server - CVE-2020-29444 |