Uploaded image for project: 'Jira Cloud'
  1. Jira Cloud
  2. JRACLOUD-35603

XSS in Dashboard

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • High
    • None

    Description

      NOTE: This bug report is for JIRA Cloud. Using JIRA Server? See the corresponding bug report.

      However, I am still investigating the original issue (JST-80496) but it seems there is a potential for XSS in Dashboard Gadgets.
      I was able to reproduce this on Firefox, Linux:

      So, access JIRA and login. Open a new tab and access the treasury.gov site. Use this same tab that has the treasury site opened to access JIRA.

      From my current investigation:

      • treasury.gov stores some user tracking data in window.name JS parameter. its value is passed across visits (and sites opened in the same tab)
      • gadgets are reading values from window.name and somehow its content is injected to the page

      cc: ohernandez@atlassian.com

      Attachments

        Issue Links

          Activity

            People

              ohernandez@atlassian.com Oswaldo Hernandez (Inactive)
              mnowakowski Maciej Nowakowski
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: