Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-9627

Velocity does not automatically escape HTML entities when substituting variables

XMLWordPrintable

      Velocity should automatically escape (encode) HTML entities in variables it interpolates in markup. This would remove the need for explicitly escaping variables using $generalUtil.htmlEncode, and fix lots of XSS bugs including ones we haven't discovered yet.

      This affects all versions of Confluence.

            christopher.owen@atlassian.com Christopher Owen [Atlassian]
            matt@atlassian.com Matt Ryall
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: