Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-5362

XSS in the listApplicationLinks resource of the Application links plugin - CVE-2018-20239

      The version of the Application Links plugin used in Crowd before version 3.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. See https://ecosystem.atlassian.net/browse/APL-1373 for more details.

            [CWD-5362] XSS in the listApplicationLinks resource of the Application links plugin - CVE-2018-20239

            Daniel Serkowski made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 431383 ]
            Esteban Casuscelli made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 630363 ]
            Esteban Casuscelli made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 630363 ]
            Esteban Casuscelli made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 630434 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 - restricted [ 3102606 ] New: JAC Bug Workflow v3 [ 3365946 ]
            Gaurav Agarwal (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 431383 ]
            David Black made changes -
            Remote Link New: This issue links to "APL-1373 (Ecosystem Jira)" [ 421480 ]
            David Black made changes -
            Labels Original: CVE-2018-20239 advisory-released cvss-medium patch-management security New: CVE-2018-20239 advisory advisory-released cvss-medium patch-management security xss
            David Black made changes -
            Labels Original: CVE-2018-20239 cvss-medium patch-management security New: CVE-2018-20239 advisory-released cvss-medium patch-management security
            David Black made changes -
            Description Original: The version of the Application Links plugin used in Crowd before version 3.5.0 and from version 3.4.0 before version 3.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. See https://ecosystem.atlassian.net/browse/APL-1373 for more details. New: The version of the Application Links plugin used in Crowd before version 3.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. See https://ecosystem.atlassian.net/browse/APL-1373 for more details.

              Unassigned Unassigned
              dblack David Black
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: