-
Bug
-
Resolution: Fixed
-
Highest
-
2.6.0
-
None
Velocity should automatically escape (encode) HTML entities in variables it interpolates in markup. This would remove the need for explicitly escaping variables using $generalUtil.htmlEncode, and fix lots of XSS bugs including ones we haven't discovered yet.
This affects all versions of Confluence.
- blocks
-
CONFSERVER-7615 XSS bug: usernames not HTML-encoded in all places
- Closed
-
CONFSERVER-9559 Cross-site scripting vulnerability in /dashboard.action
- Closed
-
CONFSERVER-11005 XSS vulnerability in signup actions
- Closed
- is related to
-
CONFSERVER-12335 Write developer documentation for HtmlSafe Velocity encoding
- Closed
-
CONFSERVER-12573 Enable automatic HTML encoding by default
- Closed
- relates to
-
CONFSERVER-9640 Upgrade Confluence's Velocity dependency to 1.5
- Closed