Bug 922740 (CVE-2015-0284) - VUL-0: CVE-2015-0284: spacewalk: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Summary: VUL-0: CVE-2015-0284: spacewalk: stored XSS in user details fields (incomplet...
Status: RESOLVED FIXED
: CVE-2016-2144 (view as bug list)
Alias: CVE-2015-0284
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Silvio Moioli
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:RedHat:CVE-2014-7811:3.5:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-17 15:10 UTC by Marcus Meissner
Modified: 2016-05-20 00:14 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2015-03-17 15:10:31 UTC
embargoed via rh bugzilla

https://bugzilla.redhat.com/show_bug.cgi?id=1181472

Jan Hutař reports:

There is stored XSS vulnerability in user details field in Satellite server, they can be exploited by using the REST API to send XML data containing malformed data.


(again this is currently all information)
Comment 1 Swamp Workflow Management 2015-03-17 23:01:10 UTC
bugbot adjusting priority
Comment 3 Johannes Segitz 2015-06-25 11:23:49 UTC
is public, but still not more information available
Comment 4 Marcus Meissner 2016-03-08 16:35:47 UTC
*** Bug 969911 has been marked as a duplicate of this bug. ***
Comment 5 Marcus Meissner 2016-03-08 16:38:53 UTC
External reference:
spacewalk git dd418384171473c3e31386a1b4792f8c555dc744
spacewalk git f3792c79c1c251a49cc4e382be8591636326a794
Comment 6 Silvio Moioli 2016-03-14 07:52:59 UTC
PR for 2.1 opened, pending review: https://github.com/SUSE/spacewalk/pull/529

3.0 not affected.
Comment 7 Silvio Moioli 2016-04-19 20:35:41 UTC
Merged, closing this bug.

Thanks everyone for cooperation.
Comment 8 Swamp Workflow Management 2016-05-20 00:11:49 UTC
SUSE-SU-2016:1367-1: An update that solves 5 vulnerabilities and has 24 fixes is now available.

Category: security (moderate)
Bug References: 922740,924298,958923,961002,961565,962253,966622,966737,966890,968257,968406,968851,970223,970425,970550,970672,970901,970989,971237,972341,973162,973432,973550,974010,974011,974315,976194,976826,978166
CVE References: CVE-2015-0284,CVE-2016-2103,CVE-2016-2104,CVE-2016-3079,CVE-2016-3097
Sources used:
SUSE Manager 2.1 (src):    cobbler-2.2.2-0.61.2, osad-5.11.33.11-15.2, rhnlib-2.5.69.8-11.2, spacewalk-backend-2.1.55.25-24.5, spacewalk-branding-2.1.33.16-18.2, spacewalk-certs-tools-2.1.6.10-18.3, spacewalk-java-2.1.165.23-20.1, spacewalk-utils-2.1.27.15-12.7, suseRegisterInfo-2.1.12-14.2, susemanager-2.1.24-23.1, susemanager-sync-data-2.1.15-30.2, susemanager-tftpsync-2.1.2-11.2