Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-7118

XSS vulnerability in the Test Run page at the Cucumber step results

    XporterXMLWordPrintable

Details

    • XRAY 2021 Sprint 3, XRAY 2021 Sprint 4
    • OK

    Description

      Due to a XSS vulnerability, it's possible to inject JS code into the HTML code of the Test Run page, when importing Cucumber execution results.

      Steps to reproduce

      Step Result
      Inject the <script> in the error message - Cucumber Execution report
      Import the Execution report
      Go to the Test Run page and expand the cucumber steps clicking on the blue triangle

      Attachments

        Activity

          People

            ipvm Isabel Moreira
            maaf Miguel Fernandes
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 day, 1 hour, 30 minutes
                1d 1h 30m