Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-66195

XSS Vulnerability in JIRA Issue Export

    XMLWordPrintable

Details

    Description

      A search endpoint is vulnerable to an XSS injection in certain cases.

      Normally, the browser will urlencode its requests, but some proxy servers and load balancers will decode URL data by default. (see http://stackoverflow.com/questions/31266629/nginx-encoding-normalizing-part-of-uri)

      Attachments

        Activity

          People

            kkolonko Kamil Kolonko
            f00499ec2014 Micah Figone
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: