Atlassian JIRA < 3.13.3 DWR 'c0-id' XSS

This script is Copyright (C) 2009-2012 Tenable Network Security, Inc.


Synopsis :

The remote web server contains an application that is affected by
a cross-site scripting vulnerability.

Description :

The remote host is running Atlassian JIRA, a web-based application
for bug tracking, issue tracking, and project management. The
version installed on the remote web server is affected by a cross-
site scripting issue due to a failure to sanitize input to the
'c0-id' parameter during a DWR call.

Note that other issues have been reported with JIRA versions prior to
3.13.3, although Nessus has not tested for them. Refer to the
advisory for more information.

See also :

http://jira.atlassian.com/browse/CONF-11808
http://jira.atlassian.com/browse/JRA-16072
http://www.nessus.org/u?cfe21f94

Solution :

Either apply the patches referenced in the advisory above or upgrade
to JIRA 3.13.3 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 36184 (jira_3_13_3.nasl)

Bugtraq ID: 34342

CVE ID: