We have identified and fixed several reflected and persisted cross-site scripting (XSS) vulnerabilities that affect GreenHopper instances, including publicly available instances (that is, Internet-facing servers). XSS vulnerabilities allow an attacker to embed their own JavaScript into a GreenHopper page.
More details are available in the advisory at https://confluence.atlassian.com/display/GH/GreenHopper+Security+Advisory+2012-08-21
[JSWCLOUD-5642] Cross Site Scripting Vulnerabilities
Workflow | Original: JSWCLOUD Bug Workflow [ 3193008 ] | New: JAC Bug Workflow v3 [ 3474184 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1884051 ] | New: JSWCLOUD Bug Workflow [ 3193008 ] |
Project Import | New: Sun Apr 02 01:01:23 UTC 2017 [ 1491094883663 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 [ 909815 ] | New: JIRA Bug Workflow w Kanban v6 - Restricted [ 1550480 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 127602 ] | New: This issue links to "Page (Atlassian Documentation)" [ 127602 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 127602 ] | New: This issue links to "Page (Atlassian Documentation)" [ 127602 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 127602 ] | New: This issue links to "Page (Atlassian Documentation)" [ 127602 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 127602 ] | New: This issue links to "Page (Atlassian Documentation)" [ 127602 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 127602 ] | New: This issue links to "Page (Atlassian Documentation)" [ 127602 ] |
Remote Link | Original: This issue links to "Page (Atlassian Documentation)" [ 127602 ] | New: This issue links to "Page (Atlassian Documentation)" [ 127602 ] |