-
Bug
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
None
-
4.8
-
NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.
A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name.
- relates to
-
JRACLOUD-61861 CVE-2016-4318: XSS vulnerability in role name on /project/ViewDefaultProjectRoleActors.jspa
-
- Closed
-
[JRASERVER-61861] CVE-2016-4318: XSS vulnerability in role name on /project/ViewDefaultProjectRoleActors.jspa
Workflow | Original: JAC Bug Workflow v2 [ 2841680 ] | New: JAC Bug Workflow v3 [ 2919443 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2573493 ] | New: JAC Bug Workflow v2 [ 2841680 ] |
Status | Original: Closed [ 6 ] | New: Resolved [ 5 ] |
Fix Version/s | New: 7.1.9 [ 64205 ] | |
Fix Version/s | Original: 7.1.9 Server [ 62034 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1554274 ] | New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2573493 ] |
Fix Version/s | New: Available in Cloud [ 77401 ] | |
Fix Version/s | Original: 1000.35.0 Cloud [ 62057 ] |
Description | Original: A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name. |
New:
{panel:bgColor=#e7f4fa} *NOTE:* This bug report is for *JIRA Server*. Using *JIRA Cloud*? [See the corresponding bug report|http://jira.atlassian.com/browse/JRACLOUD-61861]. {panel} A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name. |
Link |
New:
This issue relates to |
Component/s | New: Project Administration - Users and Roles [ 11832 ] |
Description | Original: A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource. | New: A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name. |
Security | Original: Reporter and Atlassian Staff [ 10751 ] |