Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-36251

XSS in Pie Chart and Heat Map

    XMLWordPrintable

Details

    Description

      NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.

      Pie Chart and Heat Map have a persistent XSS vulnerability.

      When HTML tag is stored as Custom Field name (e.g. <script>) then after configuring Pie Chart (or Heat Map) and pressing Save the gadget is not shown but stays at configuration state.

      Only after refreshing the gadget displays information.

      Attachments

        1. PieChart.png
          PieChart.png
          34 kB
        2. xss.png
          xss.png
          157 kB

        Issue Links

          Activity

            People

              ohernandez@atlassian.com Oswaldo Hernandez (Inactive)
              ialexeyenko Ignat (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: