#VU65891 Cross-site scripting in Atlassian products - CVE-2022-26136
Published: July 29, 2022
Atlassian Bamboo
Bitbucket Data Center
Confluence Data Center
Crowd Data Center
Jira Service Management Server
Jira Software
Atlassian Crucible
Atlassian Fisheye
Atlassian
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the Servlet Filter. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- https://jira.atlassian.com/browse/CWD-5815
- https://jira.atlassian.com/browse/FE-7410
- https://jira.atlassian.com/browse/JRASERVER-73897
- https://jira.atlassian.com/browse/BAM-21795
- https://jira.atlassian.com/browse/JSDSERVER-11863
- https://jira.atlassian.com/browse/CONFSERVER-79476
- https://jira.atlassian.com/browse/CRUC-8541
- https://jira.atlassian.com/browse/BSERV-13370