javascript: and mailto: links are allowed in JIRA integration settings
Low
H
HackerOne
Submitted None
Actions:
Reported by
jamesclyde
Vulnerability Details
Technical details and impact analysis
**Summary:**
For new feature settings, you accept website URLs like blocked:// or blocked:// in base urls. Even https://evil.com works, this needs to be stripped, this can be used to create another integrations without
### Steps To Reproduce
1. https://hackerone.com/(Team)/integrations/jira/edit
2. Try in Base URL: blocked:// or blocked://
3. It will save and opens it everytime when escalate
### Optional: Your Environment (Browser version, Device, etc)
Works in all browsers
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate
Submitted
Weakness
Violation of Secure Design Principles