-
Bug
-
Resolution: Fixed
-
Low
-
4.6.1
-
Severity 2 - Major
-
The version of the Application Links plugin used in Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. See https://ecosystem.atlassian.net/browse/APL-1373 for more details.
- is related to
-
FE-7161 XSS in the listApplicationLinks resource of the Application links plugin - CVE-2018-20239
-
- Closed
-
-
APL-1373 Loading...
- relates to
-
SECURITY-1179 Failed to load
[CRUC-8379] XSS in the listApplicationLinks resource of the Application links plugin - CVE-2018-20239
Remote Link | Original: This issue links to "APL-1373 (Ecosystem Jira)" [ 421477 ] | New: This issue links to "APL-1373 (Ecosystem JIRA)" [ 421477 ] |
Labels | Original: CVE-2018-20239 cvss-medium security xss | New: CVE-2018-20239 advisory advisory-released cvss-medium patch-management security xss |
Summary | Original: XSS in Application Links through the applinkStartingUrl parameter - CVE-2018-20239 | New: XSS in the listApplicationLinks resource of the Application links plugin - CVE-2018-20239 |
Remote Link | New: This issue links to "APL-1373 (Ecosystem Jira)" [ 421477 ] |
Labels | Original: cvss-medium security xss | New: CVE-2018-20239 cvss-medium security xss |
Security | Original: Atlassian Staff [ 10750 ] |
Description | Original: Application links in Atlassian Fisheye Crucible Development before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. | New: The version of the Application Links plugin used in Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. See https://ecosystem.atlassian.net/browse/APL-1373 for more details. |
Summary | Original: XSS in Application Links through the applinkStartingUrl parameter - CVE-TBD | New: XSS in Application Links through the applinkStartingUrl parameter - CVE-2018-20239 |
Remote Link | New: This issue links to "SECURITY-1179 (Security JIRA (CYBER/J))" [ 415053 ] |