The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter as the fix for CVE-2017-18039 was incomplete.

            [JRASERVER-67526] XSS in IncomingMailServer resource - CVE-2018-13387

            set-jac-bot made changes -
            Bugfix Automation Bot made changes -
            Minimum Version New: 7.06
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2831841 ] New: JAC Bug Workflow v3 [ 2929644 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Symptom Severity Original: Major [ 14431 ] New: Severity 2 - Major [ 15831 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2706016 ] New: JAC Bug Workflow v2 [ 2831841 ]
            Status Original: Closed [ 6 ] New: Resolved [ 5 ]
            Brian Cruz (Inactive) made changes -
            Fix Version/s New: 7.8.5 [ 79812 ]
            Brian Cruz (Inactive) made changes -
            Fix Version/s Original: 7.8.5 [ 79812 ]
            David Black made changes -
            Labels Original: CVE-2018-13387 advisory advisory-to-release cvss-medium rxss security triaged xss New: CVE-2018-13387 advisory advisory-released cvss-medium rxss security triaged xss
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release cvss-medium rxss security triaged xss New: CVE-2018-13387 advisory advisory-to-release cvss-medium rxss security triaged xss

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: