Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-21022

issuelinkssmall.jsp has an XSS hole via the URL used to access it

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • High
    • 4.1.1, 4.2
    • 3.12, 3.12.1, 3.12.2, 3.12.3, 3.13, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.13.5, 4.0, 4.0.1, 4.0.2, 4.1
    • Issue - Actions

    Description

      The issuelinkssmall.jsp has an XSS hole, where if the URL contains an XSS string, the ww:url tag will include that tag in the page because the value attribute was left empty.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              andreask@atlassian.com Andreas Knecht (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: