First published: Tue Dec 05 2017(Updated: )
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence | <6.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16856 is a vulnerability in Atlassian Confluence before version 6.5.2 that allows remote attackers to inject arbitrary HTML or JavaScript via cross-site scripting (XSS) vulnerabilities.
CVE-2017-16856 affects Atlassian Confluence before version 6.5.2.
CVE-2017-16856 has a severity keyword of 'medium' and a severity value of 6.1.
Remote attackers can exploit CVE-2017-16856 by injecting arbitrary HTML or JavaScript via cross-site scripting (XSS) vulnerabilities in various RSS properties.
Yes, you can find more information about CVE-2017-16856 at the following sources: [1] http://www.securityfocus.com/bid/102094, [2] https://jira.atlassian.com/browse/CONFSERVER-54395