Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 369137 (CVE-2011-1838) - www-apps/twiki: Cross-site Scripting Vulnerability (CVE-2011-1838)
Summary: www-apps/twiki: Cross-site Scripting Vulnerability (CVE-2011-1838)
Status: RESOLVED FIXED
Alias: CVE-2011-1838
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://twiki.org/cgi-bin/view/Codev/S...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-05-29 03:56 UTC by Tim Sammut (RETIRED)
Modified: 2012-03-03 20:17 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-05-29 03:56:06 UTC
From the upstream advisory at $URL:

Attack Vectors

Attack can be done by viewing wiki pages or by logging in by issuing HTTP GET requests towards the TWiki server (usually port 80/TCP).

Impact

Specially crafted parameters open up XSS (Cross-Site Scripting) attacks.

Severity Level

The TWiki SecurityTeam triaged this issue as documented in TWikiSecurityAlertProcess and assigned the following severity level:

    * Severity 3 issue: TWiki content or browser is compromised. 


There is a new release available, and a patch at $URL.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-06-13 16:55:25 UTC
CVE-2011-1838 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1838):
  Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in
  TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or
  HTML via the origurl parameter to a (1) view script or (2) login script.
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2012-03-03 18:47:43 UTC
package has been removed from tree
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2012-03-03 20:17:11 UTC
(In reply to comment #2)
> package has been removed from tree

Thanks. Closing noglsa since twiki was only ever ~arch.