Bug 996004 (CVE-2016-7103) - VUL-1: CVE-2016-7103: python-XStatic-jquery-ui: cross-site scripting in dialog closeText
Summary: VUL-1: CVE-2016-7103: python-XStatic-jquery-ui: cross-site scripting in dialo...
Status: RESOLVED FIXED
Alias: CVE-2016-7103
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/172205/
Whiteboard: CVSSv2:NVD:CVE-2016-7103:4.3:(AV:N/AC...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-29 11:33 UTC by Alexander Bergmann
Modified: 2019-10-02 14:47 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-08-29 11:33:28 UTC
rh#1360286

It was found that jQuery-UI, a library for manipulating UI elements via jQuery, has a cross site scripting (XSS) vulnerability in the closeText parameter of the dialog function. If an application passes user input to this parameter, it may be vulnerable to XSS.

Upstream patch:
https://github.com/jquery/jquery-ui/pull/1622

External References:
https://nodesecurity.io/advisories/127

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1360286
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7103
Comment 1 Swamp Workflow Management 2016-08-29 22:00:33 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2017-08-03 12:30:26 UTC
Dirk, upstream is at 1.12.0.1.
https://pypi.python.org/pypi/XStatic-jquery-ui

This package is not in Factory. Please bring this into Factory as per our policy!
Comment 4 Andreas Stieger 2017-08-08 17:32:17 UTC
Passing attacker controlled content to the closeText is unlikely. VUL-1.
Comment 7 Swamp Workflow Management 2017-09-05 16:09:00 UTC
SUSE-SU-2017:2351-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 996004
CVE References: CVE-2016-7103
Sources used:
SUSE OpenStack Cloud 7 (src):    python-XStatic-jquery-ui-1.11.0.1-2.3.1
Comment 8 Marcus Meissner 2019-05-29 06:50:55 UTC
done