Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8439

XSS in the the review resource through the name of a missing branch - CVE-2019-15007

      The review resource in Atlassian Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.

            [CRUC-8439] XSS in the the review resource through the name of a missing branch - CVE-2019-15007

            David Black made changes -
            Labels Original: CVE-2019-15007 advisory advisory-to-release bugbounty cvss-medium security xss New: CVE-2019-15007 advisory advisory-released bugbounty cvss-medium security xss
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            Marek Parfianowicz made changes -
            Affects Version/s New: N/A [ 54415 ]
            Affects Version/s Original: 4.7.1 [ 87093 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release bugbounty cvss-medium security xss New: CVE-2019-15007 advisory advisory-to-release bugbounty cvss-medium security xss
            David Black made changes -
            Summary Original: XSS in the the review resource through the name of a missing branch New: XSS in the the review resource through the name of a missing branch - CVE-2019-15007
            David Black made changes -
            Link New: This issue is related to CRUC-8440 [ CRUC-8440 ]
            David Black made changes -
            Link Original: This issue was cloned as CRUC-8440 [ CRUC-8440 ]
            David Black made changes -
            Link New: This issue was cloned as CRUC-8440 [ CRUC-8440 ]
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Summary Original: XSS in the the review resource New: XSS in the the review resource through the name of a missing branch

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: