Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-30363

XSS in Issue Collector

    XMLWordPrintable

Details

    Description

      Hi Atlassian!

      There is a XSS vulnerability in the issue collector:

      File: /atlassian-jira-5.1.8-source/jira-issue-collector-plugin/src/main/resources/templates/view-collector.vm
      Line 82: <td class="nav summary"><a href="${baseurl}/browse/${issue.key}">${issue.summary}</a>

      Anonymous users can inject JS in the issue summary which usually will be executed by users with extended permissions.

      Best regards,
      Conrad

      Attachments

        1. collector1.png
          collector1.png
          44 kB
        2. collector2.png
          collector2.png
          85 kB
        3. collector3.png
          collector3.png
          90 kB

        Activity

          People

            edalgliesh Eric Dalgliesh
            c9eeee349378 ConradR
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: