Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-94153

Page tree on side bar not rendering page title correctly when title contains path traversal strings

      Issue Summary

      This is reproducible on Data Center: (yes)

      If the page title contains one of the following characters sets, the page tree displays as 

      $htmlUtil.htmlEncode($content.displayTitle)

      ../ 
      ..\ 
      /.. 
      \..
      

      Steps to Reproduce

      • Create a page, with one of the above strings in the title.
      • Publish/save
      • Check the links in the Page Tree on side bar

      Expected Results

      All the links should display encoded results of displayTitle.

      Actual Results

      Title is not encoded correctly

      Workaround

      There is no obvious workaround found.

            [CONFSERVER-94153] Page tree on side bar not rendering page title correctly when title contains path traversal strings

            It is not fixed in v7.19.19.

            KVB Collab Team added a comment - It is not fixed in v7.19.19.

            A fix for this issue is available in Confluence Server and Data Center 8.5.6.
            Upgrade now or check out the Release Notes to see what other issues are resolved.

            Aakash Jain added a comment - A fix for this issue is available in Confluence Server and Data Center 8.5.6. Upgrade now or check out the Release Notes to see what other issues are resolved.

            A fix for this issue is available in Confluence Server and Data Center 7.19.19.
            Upgrade now or check out the Release Notes to see what other issues are resolved.

            Aakash Jain added a comment - A fix for this issue is available in Confluence Server and Data Center 7.19.19. Upgrade now or check out the Release Notes to see what other issues are resolved.

              a2879c3b3278 Jordan Anslow
              8b5c2ab424ac Jing Zheng
              Affected customers:
              2 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: