-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Low
-
None
-
Affects Version/s: 10.0.0, 10.3.15
-
Component/s: Email notifications
-
None
-
10
-
5
-
Severity 2 - Major
-
19
Issue Summary
When the string ../ is placed in the issue Description field, the body of the email notification is replaced with a large exception text and stack trace. When it is placed in a comment, the comment is replaced by the string $attachmentsManager.inlineImages($textParagraph)
We suspect this is caused by the changes made in Jira 10 to velocity templates
This behaviour is problematic because:
- The content of the updated field is not normally displayed, and,
- If the string is being redacted for security reasons, the way it's being presented to the user presents as a bug, not a deliberate sanitation
Steps to Reproduce
- Jira v10.3.15
- Integrate with an outbound mail server
- Disable Batching email notifications
- Create an issue
- Edit the issue's Description, adding the offending string
- Receive the update notification in your email client
Expected Results
The email content is sent verbatim
At the very least, if the offending characters are not permitted, simply replace only those characters with an empty string.
Actual Results
If the action was to add the offending string, the email body is mostly replaced with the following content:
An error occurred whilst rendering this message. Please contact the administrators, and inform them of this bug. Details: ------- org.apache.velocity.exception.MethodInvocationException: Invocation of method 'diff' in class com.atlassian.jira.mail.DiffUtils threw exception java.lang.NullPointerException: Cannot invoke "String.length()" because "newText" is null at templates/email/html/includes/changelog-issue-description.vm[line 12, column 39] at org.apache.velocity.runtime.parser.node.ASTMethod.handleInvocationException(ASTMethod.java:342) at org.apache.velocity.runtime.parser.node.ASTMethod.execute(ASTMethod.java:284) at org.apache.velocity.runtime.parser.node.ASTReference.execute(ASTReference.java:262) at org.apache.velocity.runtime.parser.node.ASTReference.value(ASTReference.java:507) at org.apache.velocity.runtime.parser.node.ASTExpression.value(ASTExpression.java:71) at org.apache.velocity.runtime.parser.node.ASTSetDirective.render(ASTSetDirective.java:142) at org.apache.velocity.runtime.parser.node.ASTBlock.render(ASTBlock.java:72) at org.apache.velocity.runtime.parser.node.ASTIfStatement.render(ASTIfStatement.java:87) <SNIP>
If the action was to remove the offending string, the email body is mostly replaced with the following content:
An error occurred whilst rendering this message. Please contact the administrators, and inform them of this bug. Details: ------- org.apache.velocity.exception.MethodInvocationException: Invocation of method 'diff' in class com.atlassian.jira.mail.DiffUtils threw exception java.lang.NullPointerException: Cannot invoke "String.length()" because "oldText" is null at templates/email/html/includes/changelog-issue-description.vm[line 12, column 39] at org.apache.velocity.runtime.parser.node.ASTMethod.handleInvocationException(ASTMethod.java:342) at org.apache.velocity.runtime.parser.node.ASTMethod.execute(ASTMethod.java:284) at org.apache.velocity.runtime.parser.node.ASTReference.execute(ASTReference.java:262) at org.apache.velocity.runtime.parser.node.ASTReference.value(ASTReference.java:507) at org.apache.velocity.runtime.parser.node.ASTExpression.value(ASTExpression.java:71) at org.apache.velocity.runtime.parser.node.ASTSetDirective.render(ASTSetDirective.java:142) at org.apache.velocity.runtime.parser.node.ASTBlock.render(ASTBlock.java:72) at org.apache.velocity.runtime.parser.node.ASTIfStatement.render(ASTIfStatement.java:87) at org.apache.velocity.runtime.parser.node.SimpleNode.render(SimpleNode.java:336) at org.apache.velocity.runtime.directive.Parse.render(Parse.java:263) at org.apache.velocity.runtime.parser.node.ASTDirective.render(ASTDirective.java:175) at org.apache.velocity.runtime.parser.node.SimpleNode.render(SimpleNode.java:336) at org.apache.velocity.runtime.RuntimeInstance.render(RuntimeInstance.java:1267) at org.apache.velocity.runtime.RuntimeInstance.evaluate(RuntimeInstance.java:1206) at org.apache.velocity.runtime.RuntimeInstance.evaluate(RuntimeInstance.java:1155) at org.apache.velocity.app.VelocityEngine.evaluate(VelocityEngine.java:219) <SNIP>
If an image is present in the description, then the content will be as follows:
An error occurred whilst rendering this message. Please contact the administrators, and inform them of this bug. Details: ------- org.apache.velocity.exception.MethodInvocationException: Invocation of method 'inlineImages' in class com.atlassian.jira.mail.util.MailAttachmentsManagerImpl threw exception java.lang.NullPointerException: Cannot invoke "java.lang.CharSequence.length()" because "this.text" is null at templates/email/html/includes/patterns/text-paragraph.vm[line 4, column 33] at org.apache.velocity.runtime.parser.node.ASTMethod.handleInvocationException(ASTMethod.java:342) at org.apache.velocity.runtime.parser.node.ASTMethod.execute(ASTMethod.java:284) at org.apache.velocity.runtime.parser.node.ASTReference.execute(ASTReference.java:262) at org.apache.velocity.runtime.parser.node.ASTReference.render(ASTReference.java:342) at org.apache.velocity.runtime.parser.node.SimpleNode.render(SimpleNode.java:336) at org.apache.velocity.runtime.directive.Parse.render(Parse.java:263) at org.apache.velocity.runtime.parser.node.ASTDirective.render(ASTDirective.java:175
Furthermore, the error is logged to the application logs:
Mail Queue Service [velocity] Found a potential path traversal attempt in the parameters: [<p style='margin-top:0;margin-bottom:10px;'>...\DB</p>] of method: inlineImages from object of class: com.atlassian.jira.mail.util.MailAttachmentsManagerImpl, rejecting due to security restrictions
Here is how the user is presented with the update:
Workaround
Currently there is no known workaround for this behavior. A workaround will be added here when available