---
title: "Comala Workflows Security Advisory 2016-09-16"
canonical: "https://support.appfire.com/space/CDML/650251496/Comala%20Workflows%20Security%20Advisory%202016-09-16"
format: markdown
---
> Macro (aura-html)


## Overview

This advisory discloses security vulnerabilities found and fixed in **Comala Workflows**.

We recommend **[upgrading ](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649594169)**[ ](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649594169)**[Comala Workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649594169)** to the latest supported version.

## Affected Versions

The vulnerability affects **Comala Workflows 4.8 through to 4.13.3**.

The 4.13.4 release contains a fix for the issue mentioned below.

## XSS Vulnerabilities

### Severity

Comalatech rates the severity of these issues as **Medium** according to the published [Atlassian Security Levels](https://www.atlassian.com/security/security-severity-levels).

This is an independent assessment and you should evaluate its applicability to your own IT environment.

### Description

We have fixed a reflected cross site scripting vulnerability in Comala Workflows.

### Risk Mitigation

We recommend you upgrade Comala Workflows to 4.13.4 or later.

## Acknowledgements

Comalatech would like to thank the **KPMG Security Team** for reporting this vulnerability.