Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-7000

XSS in various resources through the name of a commit author - CVE-2017-18090

      Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.

            [FE-7000] XSS in various resources through the name of a commit author - CVE-2017-18090

            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2944986 ] New: JAC Bug Workflow v3 [ 2957290 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 2594847 ] New: FE-CRUC Bug Workflow [ 2944986 ]
            David Black made changes -
            Link New: This issue is related to FE-7005 [ FE-7005 ]
            David Black made changes -
            Link Original: This issue was cloned as FE-7005 [ FE-7005 ]
            David Black made changes -
            Link New: This issue was cloned as FE-7005 [ FE-7005 ]
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Labels Original: CVE-2017-18090 advisory advisory-to-release bugbounty cvss-medium security xss New: CVE-2017-18090 advisory advisory-released bugbounty cvss-medium security xss
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Summary Original: CVE-2017-18090 New: XSS in various resources through the name of a commit author - CVE-2017-18090
            David Black made changes -
            Description Original: Various resources in Atlassian Fisheye before version 4.5.1 and before version 4.6.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in VULN_INFO. New: Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: