CVE-2017-18092: XSS
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18092?
CVE-2017-18092 is a cross site scripting (XSS) vulnerability in Atlassian Crucible before version 4.4.3 and before 4.5.0.
How does CVE-2017-18092 affect Atlassian Crucible?
CVE-2017-18092 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet in Atlassian Crucible.
What is the severity of CVE-2017-18092?
CVE-2017-18092 has a severity rating of 5.4 (medium).
How can I fix CVE-2017-18092?
To fix CVE-2017-18092, update Atlassian Crucible to version 4.4.3 or higher.
Where can I find more information about CVE-2017-18092?
You can find more information about CVE-2017-18092 at the following references: [1] http://www.securityfocus.com/bid/103082 [2] https://jira.atlassian.com/browse/CRUC-8176