We have identified and fixed a cross-site scripting (XSS) vulnerability in FishEye's Code Metrics Report plugin. This affects FishEye 2.0.x to 2.3.6 inclusive.
- An attacker might take advantage of an XSS vulnerability to steal the current session of a logged-in user.
- XSS vulnerabilities potentially allow an attacker to embed their own JavaScript into a FishEye page. An attacker's text and script might be displayed to other people viewing the page.
This issue is reported in our security advisory on this page:
https://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-10-20
You can read more about XSS attacks at cgisecurity, CERT and other places on the web: