
XSS issue resolved
We recently discovered a Cross Site Scripting vulnerability in our Metadata for Confluence App. It allows space administrators and Confluence administrators to inject Javascript code. This injected code will then affect users which either use the Metadata overview macro filter functionality or the “Add filter” CQL functionality of Confluence.
To solve this issue, please update your Metadata for Confluence app to version 3.0.8
Performance optimization
We also reduced the database usage for the app. This will mostly affect the general navigation through pages.