Description
Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) snippets in a user comment, which is not properly handled in a Confluence page, or (2) the user profile display name, which is not properly handled in a FishEye page.
Affected products
- Atlassian / Fisheye1.3 – 1.3
- Atlassian / Fisheye1.4 – 1.4
- Atlassian / Fisheye1.4.1 – 1.4.1
- Atlassian / Fisheye1.4.2 – 1.4.2
- Atlassian / Fisheye1.4.3 – 1.4.3
- Atlassian / Fisheye1.5.0 – 1.5.0
- Atlassian / Fisheye1.5.1 – 1.5.1
- Atlassian / Fisheye1.5.2 – 1.5.2
- Atlassian / Fisheye1.5.3 – 1.5.3
- Atlassian / Fisheye1.5.4 – 1.5.4
- Atlassian / Fisheye1.6.0 – 1.6.0
- Atlassian / Fisheye1.6.1 – 1.6.1
- Atlassian / Fisheye1.6.2 – 1.6.2
- Atlassian / Fisheye1.6.3 – 1.6.3
- Atlassian / Fisheye1.6.4 – 1.6.4
- Atlassian / Fisheye1.6.5.a – 1.6.5.a
- Atlassian / Fisheye1.6.6 – 1.6.6
- Atlassian / Fisheye2.0 – 2.0
- Atlassian / Fisheye2.0 – 2.0
- Atlassian / Fisheye2.0 – 2.0
- Atlassian / Fisheye2.0 – 2.0
- Atlassian / Fisheye2.0.1 – 2.0.1
- Atlassian / Fisheye2.0.2 – 2.0.2
- Atlassian / Fisheye2.0.3 – 2.0.3
- Atlassian / Fisheye2.0.4 – 2.0.4
- Atlassian / Fisheye2.0.5 – 2.0.5
- Atlassian / Fisheye2.0.6 – 2.0.6
- Atlassian / Fisheye2.1.0 – 2.1.0
- Atlassian / Fisheye2.1.1 – 2.1.1
- Atlassian / Fisheye2.1.2 – 2.1.2
- Atlassian / Fisheye2.1.3 – 2.1.3
- Atlassian / Fisheye2.1.4 – 2.1.4
- Atlassian / Fisheye2.2.0 – 2.2.0
- Atlassian / Fisheye2.2.1 – 2.2.1
- Atlassian / Fisheye2.2.3 – 2.2.3
- Atlassian / Fisheye2.3.0 – 2.3.0
- Atlassian / Fisheye2.3.1 – 2.3.1
- Atlassian / Fisheye2.3.2 – 2.3.2
- Atlassian / Fisheye2.3.3 – 2.3.3
- Atlassian / Fisheye2.3.4 – 2.3.4
- Atlassian / Fisheye2.3.5 – 2.3.5
- Atlassian / Fisheye2.3.6 – 2.3.6
- Atlassian / Fisheye2.3.7 – 2.3.7
- Atlassian / Fisheye2.3.8 – 2.3.8
- Atlassian / Fisheye2.4.0 – 2.4.0
- Atlassian / Fisheye2.4.1 – 2.4.1
- Atlassian / Fisheye2.4.2 – 2.4.2
- Atlassian / Fisheye2.4.3 – 2.4.3
- Atlassian / Fisheye2.4.4 – 2.4.4
- Atlassian / Fisheye2.4.5 – 2.4.5
- Atlassian / Fisheye2.4.6 – 2.4.6
- Atlassian / Fisheye2.5.0 – 2.5.0
- Atlassian / Fisheye2.5.1 – 2.5.1
- Atlassian / Fisheye2.5.2 – 2.5.2
- Atlassian / Fisheye2.5.3 – 2.5.3
- Atlassian / Fisheye2.5.4 – 2.5.4
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/71426
- MISChttps://jira.atlassian.com/browse/FE-3797
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/71427
- MISChttps://jira.atlassian.com/browse/FE-3798
- MISChttp://osvdb.org/77264
- MISChttp://confluence.atlassian.com/display/FISHEYE/FishEye+and+Crucible+Security+Advisory+2011-11-22
- VENDOR_ADVISORYhttp://secunia.com/advisories/46975
- MISChttp://www.securityfocus.com/bid/50762
- MISChttp://osvdb.org/77263