Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 499330 (CVE-2013-6235) - <dev-java/jamon-2.81: multiple reflected XSS vulnerabilities
Summary: <dev-java/jamon-2.81: multiple reflected XSS vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2013-6235
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-26 10:34 UTC by Agostino Sarubbo
Modified: 2016-04-03 23:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-01-26 10:34:43 UTC
From ${URL} :

Multiple non-persistent Cross-Site Scripting vulnerabilities have been identified [1] in the JAMon 
web application. JAMon contains a flaw that allows multiple reflected cross-site scripting (XSS) 
attacks. This flaw exists because certain pages do not validate input before returning it to users.

This issue is reported to affect version 2.7, and has not yet been fixed upstream.

[1] http://seclists.org/bugtraq/2014/Jan/92


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-29 07:37:24 UTC
Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

2.8.1 is available upstream.
Comment 2 James Le Cuirot gentoo-dev 2016-03-29 22:07:00 UTC
Working on it.
Comment 3 James Le Cuirot gentoo-dev 2016-04-03 21:49:48 UTC
Now bumped to 2.81 and the old version has gone. I don't think we were affected by the vulnerability as we didn't install the war file before. We do now though.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-04-03 23:36:53 UTC
@chewi, thanks for the bump and cleanup.