Bug 591345 (CVE-2010-1507) - VUL-0: CVE-2010-1507: WebYaST generates installation specific secret key during RPM installation
Summary: VUL-0: CVE-2010-1507: WebYaST generates installation specific secret key duri...
Status: RESOLVED FIXED
Alias: CVE-2010-1507
Product: WebYaST
Classification: SUSE Appliance Toolkit
Component: Architecture (show other bugs)
Version: SLE11 SP1 Beta5
Hardware: Other Other
: P2 - High : Major
Target Milestone: ApToolkit 1.0 Update
Assignee: Security Team bot
QA Contact: Josef Reidinger
URL:
Whiteboard: maint:released:sle11:34033
Keywords: security
Depends on:
Blocks:
 
Reported: 2010-03-26 07:03 UTC by Jiri Srain
Modified: 2013-11-20 07:44 UTC (History)
2 users (show)

See Also:
Found By: Development
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Josef Reidinger 2010-04-01 12:47:05 UTC
fixed in git...should this change go also to appliance 1.0???
Comment 2 Jiri Srain 2010-04-01 15:55:30 UTC
Good question. Klaus, are you aware of appliances planing to use WebYaST 1.0?

Regarding already existing appliances: They already have the key generated, therefore we should inform ISVs?

Thomas, your comment would be rather welcome...
Comment 3 Thomas Biege 2010-04-06 10:08:58 UTC
The information in the Cookie can not be trusted anymore, and the security impact depends on the application logic and Rails' session management.
Because the Cookie is the main mechanism for session management and authentication I would suggest releasing updates (assuming the deployment case of having cloned appliances exist).
Comment 4 Klaus Kämpf 2010-04-07 11:14:07 UTC
(In reply to comment #2)
> Good question. Klaus, are you aware of appliances planing to use WebYaST 1.0?
> 
Yes, Zmanda.
Comment 5 Josef Reidinger 2010-04-13 06:29:25 UTC
Patch was send to git ( I just cherry-pick so it is safe ).
Klaus - Do you want release it separately or wait until we have stack of fixes?
Klaus - Do you inform ISV which already build appliance? ( update work only if they replace config /srv/www/yastws/config/environment.rb with one from update. Then predefined key is replaced by new one. )
Comment 6 Klaus Kämpf 2010-04-13 08:16:02 UTC
(In reply to comment #5)
> Patch was send to git ( I just cherry-pick so it is safe ).
> Klaus - Do you want release it separately or wait until we have stack of fixes?

We can wait up to 1 week, but no longer.

> Klaus - Do you inform ISV which already build appliance?

No. They're supposed to watch for updates regularly.
Comment 7 Josef Reidinger 2010-04-13 11:05:04 UTC
OK, so I wait if other issue appear.
Comment 8 Ludwig Nussel 2010-04-27 08:13:32 UTC
CVE-2010-1507
Comment 9 Dirk Mueller 2010-06-25 14:52:37 UTC
now fixed in running update: 34033
Comment 10 Martin Vidner 2010-08-13 11:25:38 UTC
(In reply to comment #5)
> Patch was send to git ( I just cherry-pick so it is safe ).
Here: http://gitorious.org/opensuse/yast-rest-service/commit/55f6d58c9d9cfc5fc690d876f8bac7b20a07c79c

Can this be closed? The yast2-webservice update is covered by bnc#607684 .
Comment 11 Thomas Biege 2010-08-13 12:31:40 UTC
ok
Comment 12 Swamp Workflow Management 2010-08-18 21:09:49 UTC
Update released for: yast2-webclient-patch_updates, yast2-webservice, yast2-webservice-patches
Products:
SLE-WEBYAST 1.0 (i386, x86_64)