Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-67106

XSS in the agile wallboard gadget through quick filter names - CVE-2017-18100

      The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.

      Workaround

      Disable the gadget.

      • Navigate to Administration > Add-ons > Manage add-ons and set the filter to show Application Components.
      • Scroll down the list of plugins and expand JIRA Agile.
      • Click the "+" symbol next to the count of modules in this plugin to expand the list.
      • Scroll down until you find the Agile board gadget and set it to disabled.

            [JRASERVER-67106] XSS in the agile wallboard gadget through quick filter names - CVE-2017-18100

            set-jac-bot made changes -
            Bugfix Automation Bot made changes -
            Minimum Version New: 7.04
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2829126 ] New: JAC Bug Workflow v3 [ 2930052 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Symptom Severity Original: Major [ 14431 ] New: Severity 2 - Major [ 15831 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2655144 ] New: JAC Bug Workflow v2 [ 2829126 ]
            Ignat (Inactive) made changes -
            Status Original: Closed [ 6 ] New: Resolved [ 5 ]
            Ignat (Inactive) made changes -
            Fix Version/s New: 7.6.7 [ 79717 ]
            David Di Blasio made changes -
            Description Original: The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters. New: The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.

            h3. Workaround
            Disable the gadget.
            - Navigate to *Administration > Add-ons > Manage add-ons* and set the filter to show *Application Components*.
            - Scroll down the list of plugins and expand *JIRA Agile*.
            - Click the "+" symbol next to the count of modules in this plugin to expand the list.
            - Scroll down until you find the *Agile board gadget* and set it to disabled.
            Adrian Stephen made changes -
            Assignee Original: Adrian Stephen [ astephen@atlassian.com ]
            Adrian Stephen made changes -
            Assignee New: Adrian Stephen [ astephen@atlassian.com ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: