XSS in the invalidRedirectUrl template through the redirectUrl parameter - CVE-2017-16860

Description

The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the redirectUrl parameter link in the redirect warning message.

Environment

None

Activity

security-metrics-bot May 14, 2018 at 4:04 AM

This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 6.1 => Medium severity

Exploitability Metrics

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope Metric

Scope

Changed

Impact Metrics

Confidentiality

Low

Integrity

Low

Availability

None

https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Fixed
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Fix versions

Affects versions

Priority

Created May 14, 2018 at 4:04 AM
Updated September 25, 2024 at 2:44 AM
Resolved May 14, 2018 at 4:04 AM