Summary by Atlassian
Reflected Cross Site Scripting Attack in Slack integration in JIRA Software Server.
Reflected Cross Site Scripting Attack in Slack integration in JIRA Software Server.
There was an XSS in Slack integration in JIRA.
Jira Core Data Center
Web App
[jira_host]/slack/oauth/redirect/THMAXLURM%3Cimg%20src=x%20onerror=alert%601%60%3E
There is an XSS vulnerability in the JIRA server which could lead to the stealing of user credentials like cookies and more.
[jira_host]/slack/oauth/redirect/THMAXLURM%3Cimg%20src=x%20onerror=alert%601%60%3E
Added screenshot.