Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-8950

XSS vulnerability in app/spaces/listattachmentforspace.action

      Description:
      XSS via the "Filter By File Extension" field in app/spaces/listattachmentforspace.action.

      Exploit:
      blah"><script>alert(document.cookie)</script><x x="

            [CONFSERVER-8950] XSS vulnerability in app/spaces/listattachmentforspace.action

            Hi Christopher,

            I agree with Igor: few weeks seems a little too much to fix these bugs. I am not familiar devloping in JAVA, but this is only a small escaping/filtering issue.
            In enterprise enviroment this bugs can be very easily exploited, bacuase people rely on eachother.

            Gergely Hodicska added a comment - Hi Christopher, I agree with Igor: few weeks seems a little too much to fix these bugs. I am not familiar devloping in JAVA, but this is only a small escaping/filtering issue. In enterprise enviroment this bugs can be very easily exploited, bacuase people rely on eachother.

            Igor Minar added a comment -

            Hi Christopher,

            What is the ETA for 2.5.6? I'm surprised to see that critical issues like these are left unpatched for weeks.

            Igor Minar added a comment - Hi Christopher, What is the ETA for 2.5.6? I'm surprised to see that critical issues like these are left unpatched for weeks.

            Thanks for reporting these.

            Atlassian prioritises security related issues and as such will be addressing them as part of the 2.5.6 release. These releases happen on a 1-2 week basis.

            Christopher Owen [Atlassian] added a comment - Thanks for reporting these. Atlassian prioritises security related issues and as such will be addressing them as part of the 2.5.6 release. These releases happen on a 1-2 week basis.

              sleberrigaud Samuel Le Berrigaud
              b1e07ee35f09 Gergely Hodicska
              Affected customers:
              2 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: