-
Bug
-
Resolution: Fixed
-
Medium (View bug fix roadmap)
-
4.2, 4.3
-
None
-
4.02
-
We have identified and fixed a number of cross-site scripting (XSS) vulnerabilities in JIRA issue links and labels.
Affected versions are 4.2.x to 4.3.x
XSS vulnerabilities potentially allow an attacker to embed their own JavaScript into a JIRA page. You can read more about XSS attacks at various places on the web, including these:
- cgisecurity.com: http://www.cgisecurity.com/articles/xss-faq.shtml
- The Web Application Security Consortium: http://projects.webappsec.org/Cross-Site+Scripting
This issue is reported in our security advisory on this page:
[JRASERVER-24773] XSS Vulnerability in Issue Links and Labels
Minimum Version | New: 4.02 |
Workflow | Original: JAC Bug Workflow v2 [ 2842986 ] | New: JAC Bug Workflow v3 [ 2910001 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2577821 ] | New: JAC Bug Workflow v2 [ 2842986 ] |
Status | Original: Closed [ 6 ] | New: Resolved [ 5 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1541748 ] | New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2577821 ] |
Labels | Original: advisory cvss-high security | New: advisory affects-server cvss-high security |
Workflow | Original: JIRA Bug Workflow w Kanban v6 [ 677295 ] | New: JIRA Bug Workflow w Kanban v6 - Restricted [ 1541748 ] |
Labels | Original: advisory security | New: advisory cvss-high security |
Workflow | Original: JIRA Bug Workflow w Kanban v5 [ 642862 ] | New: JIRA Bug Workflow w Kanban v6 [ 677295 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v5 [ 296349 ] | New: JIRA Bug Workflow w Kanban v6 [ 642862 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Open [ 1 ] | New: Closed [ 6 ] |