Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-63736

XSS on Delete Webhook

    XMLWordPrintable

Details

    Description

      It was possible for users with JIRA administrator rights to perform an XSS attack through convincing another user, potentially a user with system administrators rights, to delete a specific webhook.

      Attachments

        Activity

          People

            Unassigned Unassigned
            dblack David Black
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: