Problem

      There is was error when rendering nested types of markup. In specially crafted cases, this could be used to create XSS vulnerabilities on pages that render wiki markup.

      Affected versions

      • older than 4.5.1

      Fixed versions

      • 4.5.1 and higher
      • 4.6.0 and higher

            [FE-6995] XSS via wiki markup

            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2944975 ] New: JAC Bug Workflow v3 [ 2958931 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 2510090 ] New: FE-CRUC Bug Workflow [ 2944975 ]
            David Black made changes -
            Labels Original: CVE-2017-18102 advisory fecru-published patch-management security xss New: advisory fecru-published patch-management security xss
            David Black made changes -
            Link New: This issue relates to JRASERVER-67108 [ JRASERVER-67108 ]
            David Black made changes -
            Labels Original: advisory fecru-published patch-management security xss New: CVE-2017-18102 advisory fecru-published patch-management security xss
            David Black made changes -
            Labels Original: fecru-published patch-management security xss New: advisory fecru-published patch-management security xss
            David Black made changes -
            Labels Original: fecru-published security xss New: fecru-published patch-management security xss
            David Black made changes -
            Link New: This issue is detailed by FECRU-7328 [ FECRU-7328 ]
            David Black made changes -
            Link Original: This issue is related to FECRU-7328 [ FECRU-7328 ]
            David Black made changes -
            Link New: This issue relates to CRUC-8162 [ CRUC-8162 ]

              Unassigned Unassigned
              mparfianowicz Marek Parfianowicz
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: