-
Bug
-
Resolution: Fixed
-
Medium (View bug fix roadmap)
-
7.4.4
-
7.04
-
Severity 2 - Major
-
The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.
Workaround
Disable the gadget.
- Navigate to Administration > Add-ons > Manage add-ons and set the filter to show Application Components.
- Scroll down the list of plugins and expand JIRA Agile.
- Click the "+" symbol next to the count of modules in this plugin to expand the list.
- Scroll down until you find the Agile board gadget and set it to disabled.
[JRASERVER-67106] XSS in the agile wallboard gadget through quick filter names - CVE-2017-18100
Fixed in Enterprise Release/s | New: [Download 7.6|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Minimum Version | New: 7.04 |
Workflow | Original: JAC Bug Workflow v2 [ 2829126 ] | New: JAC Bug Workflow v3 [ 2930052 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Symptom Severity | Original: Major [ 14431 ] | New: Severity 2 - Major [ 15831 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2655144 ] | New: JAC Bug Workflow v2 [ 2829126 ] |
Status | Original: Closed [ 6 ] | New: Resolved [ 5 ] |
Fix Version/s | New: 7.6.7 [ 79717 ] |
Description | Original: The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters. |
New:
The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.
h3. Workaround Disable the gadget. - Navigate to *Administration > Add-ons > Manage add-ons* and set the filter to show *Application Components*. - Scroll down the list of plugins and expand *JIRA Agile*. - Click the "+" symbol next to the count of modules in this plugin to expand the list. - Scroll down until you find the *Agile board gadget* and set it to disabled. |
Assignee | Original: Adrian Stephen [ astephen@atlassian.com ] |
Assignee | New: Adrian Stephen [ astephen@atlassian.com ] |