Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JIRA Web App Scan result: Client-side HTTP parameter pollution (reflected)

Kevin Fletcher
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 10, 2022

Is anyone familiar with this issue, or know if Jira software url-encodes all data/input in a uniform manner to prevent against such an attack? If not, can it be (@Atlassian folks)?

This was discovered with Burpsuite Pro.

https://portswigger.net/kb/issues/00501400_client-side-http-parameter-pollution-reflected

CWE-233

 

0 answers

Suggest an answer

Log in or Sign up to answer