Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-7008

XSS in various resources through the location setting of a configured repository - CVE-2017-18093

    XMLWordPrintable

    Details

      Description

      Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the location setting of a configured repository.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                security-metrics-bot SecurityB
                Participants:
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Last commented:
                  1 year, 20 weeks, 4 days ago