Executive brief
The atlasboard-atlassian-package, a library used to integrate Atlassian data into dashboards, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's web browser. By modifying issue summaries in Jira, an attacker can target users viewing those dashboards, potentially leading to unauthorized data access or account compromise. Organizations using this package should be aware that no official fix is currently available and should consider alternative solutions.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in atlasboard-atlassian-package versions prior to 0.4.2. The vulnerability stems from the package's failure to properly sanitize user-supplied input from Jira issue summaries before rendering them as HTML on a dashboard. An attacker with the ability to modify Jira ticket summaries can inject malicious JavaScript that executes in the context of any user viewing the affected dashboard. While the advisory mentions version 0.4.2, it also notes that no fix is currently available and recommends using alternative packages.
Affected products
- Atlassian atlasboard-atlassian-package < 0.4.2
Timeline
- 2020-08-31: advisory: GitHub advisory reviewed and updated.
- 2020-09-04: disclosed: Advisory published.