Currently the application will pass along whatever comes in from parameters like ticket, service, etc. They should be encoded.
CVE-2014-4172 is reserved for the defect addressed by this JIRA issue.
Currently the application will pass along whatever comes in from parameters like ticket, service, etc. They should be encoded.