CVE-2007-6617: XSS
Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6617?
CVE-2007-6617 is classified as a medium severity cross-site scripting vulnerability in JIRA Enterprise Edition.
How do I fix CVE-2007-6617?
To fix CVE-2007-6617, upgrade JIRA Enterprise Edition to version 3.12.1 or later.
What versions are affected by CVE-2007-6617?
CVE-2007-6617 affects JIRA Enterprise Edition versions prior to 3.12.1.
What type of attacks can CVE-2007-6617 allow?
CVE-2007-6617 allows remote attackers to inject arbitrary web scripts or HTML into error messages.
What component of JIRA is vulnerable in CVE-2007-6617?
The vulnerable component in CVE-2007-6617 is the 500page.jsp script.