Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-7118

XSS vulnerability in the Test Run page at the Cucumber step results

    XporterXMLWordPrintable

Details

    • XRAY 2021 Sprint 3, XRAY 2021 Sprint 4
    • OK

    Description

      Due to a XSS vulnerability, it's possible to inject JS code into the HTML code of the Test Run page, when importing Cucumber execution results.

      Steps to reproduce

      Step Result
      Inject the <script> in the error message - Cucumber Execution report
      Import the Execution report
      Go to the Test Run page and expand the cucumber steps clicking on the blue triangle

      Attachments

        1. CucResultsDoc.json
          3 kB
          Miguel Fernandes
        2. image-2021-02-04-22-49-37-286.png
          18 kB
          Miguel Fernandes
        3. image-2021-02-04-22-50-07-855.png
          63 kB
          Miguel Fernandes
        4. image-2021-02-04-22-53-36-636.png
          85 kB
          Miguel Fernandes

        Activity

          People

            ipvm Isabel Moreira [X] (Inactive)
            maaf Miguel Fernandes
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 day, 1 hour, 30 minutes
                1d 1h 30m