Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 472958 - <www-servers/resin-4.0.44: URL Cross-Site Scripting Vulnerability
Summary: <www-servers/resin-4.0.44: URL Cross-Site Scripting Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53749/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-06-11 09:04 UTC by Agostino Sarubbo
Modified: 2015-08-24 19:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-06-11 09:04:58 UTC
From ${URL} :

Description
Gjoko Krstic has discovered a vulnerability in Caucho Resin, which can 
be exploited by malicious people to conduct cross-site scripting 
attacks.

Input appended to the URL after /resin-admin/ is not properly sanitised 
before being returned to the user. This can be exploited to execute 
arbitrary HTML and script code in a user's browser session in context of 
an affected site.

The vulnerability is confirmed in version 4.0.36. Other versions may 
also be affected.


Solution
No official solution is currently available.

Provided and/or discovered by
Gjoko Krstic (LiquidWorm)

Original Advisory
ZSL-2013-5143:
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5143.php


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Patrice Clement gentoo-dev 2015-08-12 22:53:50 UTC
Security, you can close this bug once 431416 is sorted. Thank you.
Comment 2 Patrice Clement gentoo-dev 2015-08-21 12:24:14 UTC
Security, please proceed.
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-08-21 12:24:51 UTC
GLSA vote: no.
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-08-24 19:23:21 UTC
GLSA Vote: No