Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-67076

XSS in the Trello board importer resource - CVE-2017-18097

      The Trello board importer resource in Atlassian Jira before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.

            [JRASERVER-67076] XSS in the Trello board importer resource - CVE-2017-18097

            set-jac-bot made changes -
            Bugfix Automation Bot made changes -
            Minimum Version New: 7.05
            Owen made changes -
            Component/s New: Jira Importers Plugin [ 44190 ]
            Component/s Original: Backup & Restore - Import from Trello [ 44293 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2830053 ] New: JAC Bug Workflow v3 [ 2911692 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Symptom Severity Original: Major [ 14431 ] New: Severity 2 - Major [ 15831 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2653628 ] New: JAC Bug Workflow v2 [ 2830053 ]
            Status Original: Closed [ 6 ] New: Resolved [ 5 ]
            David Black made changes -
            Description Original: The Trello board importer resource in Atlassian Jira Server before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. New: The Trello board importer resource in Atlassian Jira before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.
            David Black made changes -
            Labels Original: CVE-2017-18097 advisory advisory-to-release bugbounty cvss-high security sxss xss New: CVE-2017-18097 advisory advisory-released bugbounty cvss-high security sxss xss
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Description Original: The Trello board importer resource in Atlassian Jira Server before version 7.6.1 Server and before version 7.7.0 Server allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. New: The Trello board importer resource in Atlassian Jira Server before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: