Legacy Workflows Documentation

Looks like you followed an old link. Comala Workflows is now Comala Document Management.

Please access our latest documentation here Welcome to Comala Document Management

Documentation for other versions of Comala Workflows are available too.

(info) This space is no longer being updated.

This advisory discloses security vulnerabilities found and fixed in Comala Workflows.  We recommend upgrading Comala Workflows to the latest supported version.

Affected Versions

The vulnerability affects Comala Workflows 5.0.0 through 5.1.0. The 5.1.1 release contains a fix for the issue mentioned below. Versions prior to 5.0.0 are not affected.

 

XSS Vulnerabilities

Severity

Comalatech rates the severity of these issues as Medium according to the published Atlassian Security Levels.

This is an independent assessment and you should evaluate its applicability to your own IT environment.

Description

We have fixed some persistent cross site scripting vulnerabilities in Comala Workflows.

Risk Mitigation

Sites running Comala Workflows 5.0.0-5.1.0 are recommend to upgrade to Comala Workflows to 5.1.1.


If upgrading immediately is not possible, you can limit the number of users that have the ability to exploit the vulnerabilities by restricting who can create/edit workflows to trusted users.


  • No labels