Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8044

Various XSS through a repository or review filename - CVE-2017-9508

      Various resources in Atlassian FishEye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.

            [CRUC-8044] Various XSS through a repository or review filename - CVE-2017-9508

            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2941973 ] New: JAC Bug Workflow v3 [ 2954361 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 2409566 ] New: FE-CRUC Bug Workflow [ 2941973 ]
            David Black made changes -
            Remote Link Original: This issue links to "Page (Extranet)" [ 314342 ]
            David Black made changes -
            Labels Original: CVE-2017-9508 advisory-released cvss-medium security xss New: CVE-2017-9508 advisory advisory-released cvss-medium security xss
            David Black made changes -
            Labels Original: advisory-released cvss-medium security xss New: CVE-2017-9508 advisory-released cvss-medium security xss
            David Black made changes -
            Summary Original: Various XSS through a repository or review filename New: Various XSS through a repository or review filename - CVE-2017-9508
            David Black made changes -
            Summary Original: XSS in malicious repository file New: Various XSS through a repository or review filename
            David Black made changes -
            Description Original: A malicious file added to a repository will cause an XSS to file inside of FishEye and Crucible. New: Various resources in Atlassian FishEye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Description Original: A malicious file added to a repository will cause an XSS to file inside of FishEye New: A malicious file added to a repository will cause an XSS to file inside of FishEye and Crucible.

              Unassigned Unassigned
              pswiecicki Piotr Swiecicki
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: