Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-21018

Miscellaneous support-related JSPs contain XSS holes

    XMLWordPrintable

Details

    Description

      JIRA contains a number of support related JSPs that have been added over the years. They were mostly for fighting spam and other support related tasks. Unfortunately none of these were ever tested very much and contain a lot of XSS holes. They are:

      • groupnames.jsp
      • indexbrowser.jsp
      • classpath-debug.jsp
      • viewdocument.jsp
      • cleancommentspam.jsp
      • plugin-bundles.jsp

      They should all be removed from JIRA unless we make a concentrated effort on integrating the functionality that they provide into the product!

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              andreask@atlassian.com Andreas Knecht (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: