CVE-2017-18085: XSS
Published Feb 2, 2018
·Updated
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
Affected Software
1 affected component
Atlassian Confluence<6.6.1
Event History
Feb 2, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-18085.
2
What is the severity of CVE-2017-18085?
The severity of CVE-2017-18085 is medium, with a severity value of 6.1.
3
What is the affected software of CVE-2017-18085?
The affected software of CVE-2017-18085 is Atlassian Confluence Server before version 6.6.1.
4
How does CVE-2017-18085 work?
CVE-2017-18085 works by allowing remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability through the key parameter of the viewdefaultdecorator resource.
5
Are there any available fixes for CVE-2017-18085?
Yes, updating to Atlassian Confluence Server version 6.6.1 or later will fix CVE-2017-18085.