XSS in Issue Collector

XMLWordPrintable

    • 5.01
    • 7.5

      Hi Atlassian!

      There is a XSS vulnerability in the issue collector:

      File: /atlassian-jira-5.1.8-source/jira-issue-collector-plugin/src/main/resources/templates/view-collector.vm
      Line 82: <td class="nav summary"><a href="${baseurl}/browse/${issue.key}">${issue.summary}</a>

      Anonymous users can inject JS in the issue summary which usually will be executed by users with extended permissions.

      Best regards,
      Conrad

        1. collector1.png
          44 kB
          ConradR
        2. collector2.png
          85 kB
          ConradR
        3. collector3.png
          90 kB
          ConradR

              Assignee:
              Eric Dalgliesh
              Reporter:
              ConradR
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: