-
Bug
-
Resolution: Fixed
-
Low
-
4.8.0
-
Severity 2 - Major
-
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
[FE-7282] XSS in the review resource through objectives - CVE-2020-4013
Labels | Original: advisory advisory-released bugbounty cve-2020-4013 cvss-medium release-48x release-490 security sxss xss | New: advisory advisory-released bugbounty cve-2020-4013 cvss-medium release-48x security sxss xss |
Labels | Original: advisory advisory-released bugbounty cve-2020-4013 cvss-medium release-490 security sxss xss | New: advisory advisory-released bugbounty cve-2020-4013 cvss-medium release-48x release-490 security sxss xss |
Labels | Original: advisory advisory-released bugbounty cve-2020-4013 cvss-medium security sxss xss | New: advisory advisory-released bugbounty cve-2020-4013 cvss-medium release-490 security sxss xss |
Fix Version/s | Original: 4.9.0 [ 90694 ] |
Fix Version/s | New: 4.8.3 [ 91929 ] |
Labels | Original: advisory advisory-to-release bugbounty cve-2020-4013 cvss-medium security sxss xss | New: advisory advisory-released bugbounty cve-2020-4013 cvss-medium security sxss xss |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Labels | Original: advisory advisory-to-release bugbounty cvss-medium security sxss xss | New: advisory advisory-to-release bugbounty cve-2020-4013 cvss-medium security sxss xss |
Summary | Original: XSS in Code reviews - CVE-PENDING | New: XSS in the review resource through objectives - CVE-2020-4013 |
Description | Original: Component in Atlassian Fisheye Crucible Development from version 4.8.0 before version 4.8.1 and before version 4.9.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in VULN_INFO. | New: The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives. |