-
Bug
-
Resolution: Fixed
-
High
-
None
-
None
-
Severity 2 - Major
-
Problem
There is was error when rendering nested types of markup. In specially crafted cases, this could be used to create XSS vulnerabilities on pages that render wiki markup.
Affected versions
- older than 4.5.1
Fixed versions
- 4.5.1 and higher
- 4.6.0 and higher
For more information see https://jira.atlassian.com/browse/RNDR-153 (currently restricted to atlassian staff).
- is related to
-
FE-6995 XSS via wiki markup
-
- Closed
-
- relates to
-
JRASERVER-67108 XSS in various types of nested wiki markup - CVE-2017-18102
-
- Closed
-
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 5.4 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N