The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

[Possible] Phishing by Navigating Browser Tabs

Bernardo Joaquín Diaz
October 28, 2020

Hello,

I've been reported the next Low vulnerability:

"Open windows with normal hrefs with the tag target="_blank" can modify window.opener.location and replace the parent webpage with something else, even on a different origin. "

It is located on the dropdown menu of the help option up in the nav bar. Could anyone confim me if it has a solution or has been checked?

On the vulnerability it is said that it can be fixed with rel="noopener noreferrer" added to the links to avoid a third party using window.opener.location.assign to exploit this.

 

2 answers

1 accepted

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Answer accepted
Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
October 31, 2020

Hi Bernardo,

in case the finding matches the definition of vulnerabilities I would not wait and report it to security team as stated in:

https://www.atlassian.com/trust/security/report-a-vulnerability

Cheers,
Daniel

0 votes
Guido Scollo
December 13, 2024

Hi Bernardo,

can you tell me if there is an issue opened with this vulnerability, please?