-
Bug
-
Resolution: Fixed
-
Medium
-
4.1.0, 4.4.0
-
None
-
Severity 3 - Minor
-
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.
[CRUC-8043] XSS in review dashboard through a custom filter title - CVE-2017-9507
Labels | Original: CVE-2017-9507 advisory advisory-released cvss-medium security | New: CVE-2017-9507 advisory advisory-released cvss-medium security xss |
Workflow | Original: FE-CRUC Bug Workflow [ 2941989 ] | New: JAC Bug Workflow v3 [ 2955927 ] |
Workflow | Original: FECRU Development Workflow - Triage - Restricted [ 2409565 ] | New: FE-CRUC Bug Workflow [ 2941989 ] |
Remote Link | Original: This issue links to "Page (Extranet)" [ 314235 ] |
Labels | Original: CVE-2017-9507 advisory-released cvss-medium security | New: CVE-2017-9507 advisory advisory-released cvss-medium security |
Labels | Original: advisory-released cvss-medium security | New: CVE-2017-9507 advisory-released cvss-medium security |
Summary | Original: XSS in review dashboard through a custom filter title | New: XSS in review dashboard through a custom filter title - CVE-2017-9507 |
Description | Original: The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the review filter title parameter. | New: The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter. |
Description |
Original:
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.
|
New: The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the review filter title parameter. |
Affects Version/s | New: 4.1.0 [ 61350 ] | |
Affects Version/s | Original: 3.10.4 [ 61344 ] |