-
Bug
-
Resolution: Fixed
-
High
-
2.5.4
-
None
Input in the Feed Builder is not properly handled.
Insert:
"><<script>alert('Gotcha!')</script>
as the feed name (title) and you get url like this:
Suggested fix: Escape output of title in
<link rel="alternate" type="application/atom+xml" title="" href=""/>
in the
/dashboard/doconfigurerssfeed.action
view
- relates to
-
CONFSERVER-30240 XSS in doconfigurerssfeed.action
-
- Closed
-
[CONFSERVER-8993] Reflected XSS Vulnerability in the Feed Builder
Workflow | Original: JAC Bug Workflow v3 [ 2900186 ] | New: CONFSERVER Bug Workflow v4 [ 2994821 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2795133 ] | New: JAC Bug Workflow v3 [ 2900186 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2733545 ] | New: JAC Bug Workflow v2 [ 2795133 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2398925 ] | New: JAC Bug Workflow [ 2733545 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 2297098 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2398925 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2232550 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 2297098 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2192828 ] | New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2232550 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 1932055 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2192828 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v3 [ 1732065 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 1932055 ] |
Workflow | Original: CONF Bug Subtask WF (TEMP) [ 1687606 ] | New: Confluence Workflow - Public Facing - Restricted v3 [ 1732065 ] |