6.1 introduced an xss bug in the detail view, more specifically in the epic field that displays to which epic an issue belongs to.

            [JSWSERVER-6997] XSS bug in detail view epic name lozenge rendering

            Bugfix Automation Bot made changes -
            Minimum Version New: 6.01
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2851578 ] New: JAC Bug Workflow v3 [ 2934267 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2541325 ] New: JAC Bug Workflow v2 [ 2851578 ]
            Ignat (Inactive) made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1548073 ] New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2541325 ]
            Confluence Escalation Bot (Inactive) made changes -
            Labels Original: security New: affects-server security
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v6 [ 907870 ] New: JIRA Bug Workflow w Kanban v6 - Restricted [ 1548073 ]
            Oswaldo Hernandez (Inactive) made changes -
            Workflow Original: GreenHopper Kanban Workflow 20141014 [ 745771 ] New: JIRA Bug Workflow w Kanban v6 [ 907870 ]
            mtokar.adm made changes -
            Workflow Original: GreenHopper Kanban Workflow v2 [ 454641 ] New: GreenHopper Kanban Workflow 20141014 [ 745771 ]
            VitalyA made changes -
            Labels Original: advisory-pending security New: security
            Security Original: Reporters and Developers [ 10021 ]
            VitalyA made changes -
            Labels Original: security New: advisory-pending security

              Unassigned Unassigned
              miruflin Michael Ruflin (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: