http://bugzilla.opensuse.org/show_bug.cgi?id=1158203 Bug ID: 1158203 Summary: VUL-0: CVE-2016-1000037: pagure: XSS in file attachment endpoint Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.1 Hardware: Other URL: https://smash.suse.de/issue/171382/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: atoptsoglou@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2016-1000037 It was found that Pagure served uploaded files from its attachment endpoint with content types that instructed the browser to parse HTML files, which could lead to Cross-Site Scripting attacks. Upstream patch: https://pagure.io/pagure/c/8b231cd378cf880df3bf7cd81277c1f771dab988 The release that fixes this issue is Pagure 2.3.4. References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000037 https://bugzilla.redhat.com/show_bug.cgi?id=1360627 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1000037 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000037 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorap... https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2... https://security-tracker.debian.org/tracker/CVE-2016-1000037 -- You are receiving this mail because: You are on the CC list for the bug.