CVE-2018-5229: XSS
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5229?
CVE-2018-5229 is classified as a critical vulnerability due to its potential for remote exploitation via cross-site scripting (XSS).
How do I fix CVE-2018-5229?
To fix CVE-2018-5229, upgrade Atlassian Universal Plugin Manager to version 2.22.9 or later.
What type of vulnerability is CVE-2018-5229?
CVE-2018-5229 is a cross-site scripting (XSS) vulnerability that allows for arbitrary HTML or JavaScript injection.
Who is affected by CVE-2018-5229?
Any user of Atlassian Universal Plugin Manager versions prior to 2.22.9 is affected by CVE-2018-5229.
What can attackers do exploiting CVE-2018-5229?
Attackers can inject malicious scripts that execute in the context of the user's session, potentially compromising sensitive information.