Atlassian JIRA ’name‘参数跨站脚本漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1166622 漏洞类型 跨站脚本
发布时间 2013-08-06 更新时间 2013-08-22
CVE编号 CVE-2013-5319 CNNVD-ID CNNVD-201308-124
漏洞平台 N/A CVSS评分 4.3
|漏洞来源
https://www.securityfocus.com/bid/61647
https://cxsecurity.com/issue/WLB-2013080065
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201308-124
|漏洞详情
AtlassianJIRA是澳大利亚Atlassian公司的一套缺陷跟踪管理系统。该系统主要用于对工作中各类问题、缺陷进行跟踪管理。AtlassianJIRA6.0.4及之前的版本中的AdminPanel中的secure/admin/user/views/deleteuserconfirm.jsp脚本中存在跨站脚本漏洞。远程攻击者可通过向secure/admin/user/DeleteUser!default.jspa地址传送‘name’参数,利用该漏洞注入任意Web脚本或HTML。
|漏洞EXP
?
Atlassian JIRA v6.0.3 Arbitrary HTML/Script Execution Vulnerability


Vendor: Atlassian Corporation Pty Ltd.
Product web page: https://www.atlassian.com
Affected version: 6.0.3 and 6.0.2

Summary: JIRA is an issue tracking project management software
for teams planning, building, and launching great products.

Desc: JIRA suffers from a reflected XSS issue due to a failure
to properly sanitize user-supplied input to the 'name' GET parameter
in the 'deleteuserconfirm.jsp' script. Attackers can exploit this
weakness to execute arbitrary HTML and script code in a user's browser
session.

Vulnerable JSP script location:
- jira-components/jira-webapp/src/main/webapp/secure/admin/user/views/deleteuserconfirm.jsp


Tested on: Microsoft Windows 7 Ultimate SP1 (EN)


Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
                            @zeroscience


Advisory ID: ZSL-2013-5151
Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5151.php

Vendor: https://jira.atlassian.com/browse/JRA-34160
        https://jira.atlassian.com/browse/JRA/fixforversion/33790
        https://jira.atlassian.com/browse/JRA/fixforversion/34310



25.06.2013

--


 http://localhost:8080/secure/admin/user/DeleteUser!default.jspa?name=a"><script>alert(document.cookie);</script>&returnUrl=UserBrowser.jspa
|参考资料

来源:jira.atlassian.com
链接:https://jira.atlassian.com/secure/ReleaseNote.jspa?projectId=10240&version=33790
来源:jira.atlassian.com
链接:https://jira.atlassian.com/i#browse/JRA-34160
来源:jira.atlassian.com
链接:https://jira.atlassian.com/browse/JRA/fixforversion/33790
来源:www.zeroscience.mk
链接:http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5151.php
来源:BID
名称:61647
链接:http://www.securityfocus.com/bid/61647
来源:SECUNIA
名称:54417
链接:http://secunia.com/advisories/54417
来源:packetstormsecurity.com
链接:http://packetstormsecurity.com/files/122721
来源:cxsecurity.com
链接:http://cxsecurity.com/issue/WLB-2013080065