Bug ID | 1158203 |
---|---|
Summary | VUL-0: CVE-2016-1000037: pagure: XSS in file attachment endpoint |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 15.1 |
Hardware | Other |
URL | https://smash.suse.de/issue/171382/ |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Security |
Assignee | security-team@suse.de |
Reporter | atoptsoglou@suse.com |
QA Contact | security-team@suse.de |
Found By | Security Response Team |
Blocker | --- |
CVE-2016-1000037 It was found that Pagure served uploaded files from its attachment endpoint with content types that instructed the browser to parse HTML files, which could lead to Cross-Site Scripting attacks. Upstream patch: https://pagure.io/pagure/c/8b231cd378cf880df3bf7cd81277c1f771dab988 The release that fixes this issue is Pagure 2.3.4. References: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000037 https://bugzilla.redhat.com/show_bug.cgi?id=1360627 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1000037 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000037 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7EHB2WQ46M737B2STHQTOPTBSSQJDSS/ https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000037.json https://security-tracker.debian.org/tracker/CVE-2016-1000037