Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-21017

Announcement Preview banner is a vector for an XSS attack

    XMLWordPrintable

Details

    Description

      The announcement preview banner is currently displayed via the global decorator. It can be used for an XSS attack on virtually every page, via the announcement_preview_banner_st URL parameter. We should display the preview only locally in the admin section.

      Attachments

        Activity

          People

            Unassigned Unassigned
            andreask@atlassian.com Andreas Knecht (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: