CVE-2008-6831
Description
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter in the ViewProfile page or (2) returnUrl parameter in a form, as demonstrated using secure/AddComment!default.jspa (aka "Add Comment").
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Atlassian JIRA Enterprise Edition 3.13 is vulnerable to stored and reflected XSS via the fullname and returnUrl parameters.
Vulnerability
Atlassian JIRA Enterprise Edition versions up to and including 3.13 contain multiple cross-site scripting (XSS) vulnerabilities. The ViewProfile page does not HTML-escape the fullname (Full Name) parameter, allowing stored XSS when a user's profile is viewed. Additionally, the returnUrl parameter in forms (e.g., secure/AddComment!default.jspa) is not properly sanitized, enabling reflected XSS. These issues are fixed in JIRA 3.13.1 [1].
Exploitation
For the stored XSS in ViewProfile, an attacker with the ability to create or edit a user (e.g., via public signup or direct user creation) can set a crafted fullname containing JavaScript. When another user visits that profile, the script executes in their browser session. For the reflected XSS on returnUrl, an attacker can craft a malicious link (e.g., via email or web page) that, when clicked by an authenticated JIRA user, executes arbitrary script in the context of the JIRA application. No special network position is required beyond internet access to the JIRA instance [1].
Impact
Successful exploitation allows an attacker to execute arbitrary web script or HTML in the context of the victim's browser session. This can lead to theft of session cookies or other credentials (sent to an attacker-controlled server), unauthorized actions on behalf of the victim, or potential system compromise depending on the victim's privileges. The severity is rated HIGH by Atlassian [1].
Mitigation
The vulnerabilities are fixed in JIRA 3.13.1, released on 2008-10-29 (per the advisory date). Users should upgrade to JIRA 3.13.1 or later. No patches are available for older versions. As a workaround, disable anonymous access and public signup, or restrict JIRA access to trusted groups until the upgrade can be applied [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2008-10-29nvdPatchVendor Advisory
- secunia.com/advisories/32113nvdVendor Advisory
- osvdb.org/49415nvd
- osvdb.org/49416nvd
- www.securityfocus.com/bid/31967nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46167nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46168nvd
News mentions
0No linked articles in our index yet.