---
title: "Comala Metadata Security Advisory 2020-10-27"
canonical: "https://support.appfire.com/space/COMALACM/655891209/Comala%20Metadata%20Security%20Advisory%202020-10-27"
format: markdown
---
<span style="color: #333333">This advisory discloses security vulnerabilities found and fixed in Comala Metadata. We recommend upgrading Comala Metadata to the latest supported version.</span>

## Affected Versions

<span style="color: #333333">The vulnerability affects </span>**<span style="color: #333333">Comala Metadata prior to version 4.2.4</span>**

<span style="color: #333333">The </span>**<span style="color: #333333">4.2.4 release contains a fix</span>**<span style="color: #333333"> for the issue mentioned below.</span>

## XSS Vulnerabilities

### Severity

<span style="color: #333333">Comalatech rates the severity of these issues as </span>**<span style="color: #333333">Medium</span>****<span style="color: #333333"> </span>**<span style="color: #333333"> according to the published </span>[<span style="color: #333333">Atlassian Security Levels</span>](https://www.atlassian.com/security/security-severity-levels)<span style="color: #333333">. We have ranked the vulnerability as medium because: </span>

- <span style="color: #333333">A registered user with edit permissions over pages or blog posts in the application could do the following: </span>
  - <span style="color: #333333">Session riding</span>
  - <span style="color: #333333">Stealing information and cookies</span>
  - <span style="color: #333333">Creating a phishing page within the domain</span>

<span style="color: #333333">This is an independent assessment and you should evaluate its applicability to your own IT environment.</span>

### Description

<span style="color: #333333">We have fixed some persistent cross site scripting vulnerabilities in Comala Metadata. The vulnerability could allow a user with edit permissions to use other user's session.</span>

### Risk Mitigation

<span style="color: #333333">Sites running Comala Metadata prior to version 4.2.4 are recommend to upgrade to Comala Metadata 4.2.4.</span>

<span style="color: #333333">If upgrading immediately is not possible please disable the application until you can upgrade it.</span>



> Macro (__confluenceADFMigrationUnsupportedContentInternalExtension__)