The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/102094 | Third Party Advisory VDB Entry |
https://jira.atlassian.com/browse/CONFSERVER-54395 | Issue Tracking Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: atlassian
Published: 2017-12-05T00:00:00
Updated: 2017-12-08T10:57:01
Reserved: 2017-11-16T00:00:00
Link: CVE-2017-16856
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-12-05T16:29:00.420
Modified: 2017-12-19T13:16:25.187
Link: CVE-2017-16856
JSON object: View
Redhat Information
No data.
CWE