• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Highest Highest
    • 2.2.6, 2.3.8, 2.4.0
    • None
    • None
    • None

      We have identified and fixed a cross-site scripting (XSS) vulnerability in the Crucible's edit review details screen.

      Affected versions are Crucible 2.2.0 to 2.3.7 inclusive.

      XSS vulnerabilities potentially allow an attacker to embed their own JavaScript into a FishEye/Crucible page. You can read more about XSS attacks at various places on the web, including these:

      This issue is reported in our security advisory on these pages:

            [CRUC-5345] XSS vulnerability in Edit Review Details

            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2941764 ] New: JAC Bug Workflow v3 [ 2955779 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 1512075 ] New: FE-CRUC Bug Workflow [ 2941764 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage [ 939510 ] New: FECRU Development Workflow - Triage - Restricted [ 1512075 ]
            Piotr Swiecicki made changes -
            Workflow Original: FECRU Development Workflow (Triage) [ 315654 ] New: FECRU Development Workflow - Triage [ 939510 ]
            Seb Ruiz (Inactive) made changes -
            Workflow Original: Simple review flow with triage [ 275356 ] New: FECRU Development Workflow (Triage) [ 315654 ]
            Andrew made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Reopened [ 4 ] New: Closed [ 6 ]
            Andrew made changes -
            Security Original: Reporters and Developers [ 10090 ]
            Andrew made changes -
            Resolution Original: Fixed [ 1 ]
            Status Original: Closed [ 6 ] New: Reopened [ 4 ]
            Andrew made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]
            Andrew made changes -
            Link New: This issue is related to CRUC-5306 [ CRUC-5306 ]

              Unassigned Unassigned
              alui Andrew
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: