-
Bug
-
Resolution: Fixed
-
High (View bug fix roadmap)
-
7.5.0
-
7.05
-
Severity 2 - Major
-
The Trello board importer resource in Atlassian Jira before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.
[JRASERVER-67076] XSS in the Trello board importer resource - CVE-2017-18097
Fixed in Enterprise Release/s | New: [Download 7.6|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Minimum Version | New: 7.05 |
Component/s | New: Jira Importers Plugin [ 44190 ] | |
Component/s | Original: Backup & Restore - Import from Trello [ 44293 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2830053 ] | New: JAC Bug Workflow v3 [ 2911692 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Symptom Severity | Original: Major [ 14431 ] | New: Severity 2 - Major [ 15831 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2653628 ] | New: JAC Bug Workflow v2 [ 2830053 ] |
Status | Original: Closed [ 6 ] | New: Resolved [ 5 ] |
Description | Original: The Trello board importer resource in Atlassian Jira Server before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. | New: The Trello board importer resource in Atlassian Jira before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. |
Labels | Original: CVE-2017-18097 advisory advisory-to-release bugbounty cvss-high security sxss xss | New: CVE-2017-18097 advisory advisory-released bugbounty cvss-high security sxss xss |
Security | Original: Atlassian Staff [ 10750 ] |
Description | Original: The Trello board importer resource in Atlassian Jira Server before version 7.6.1 Server and before version 7.7.0 Server allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. | New: The Trello board importer resource in Atlassian Jira Server before version 7.6.1 and before version 7.7.0 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. |