Bug 1117205 (CVE-2014-4722)

Summary: CVE-2014-4722 ocsinventory: multiple stored XSS vulnerabilities
Product: [Other] Security Response Reporter: Vasyl Kaigorodov <vkaigoro>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fedora, jrusnack, xavier
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:33:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1117207, 1117208    
Bug Blocks:    

Description Vasyl Kaigorodov 2014-07-08 09:33:04 UTC
It was discovered [1] that OCS Inventory web interface has multiple stored XSS vulnerabilities.

Stored attacks are those where the injected script is permanently stored
on the target servers, such as in a database, in a message forum,
visitor log, comment field, etc. The victim then retrieves the malicious
script from the server when it requests the stored information.

Upstream commits which fix these issues:

2.0 branch: http://bazaar.launchpad.net/~ocsinventory-core/ocsinventory-ocsreports/stable-2.0/revision/834
2.1 branch: http://bazaar.launchpad.net/~ocsinventory-dev/ocsinventory-ocsreports/stable-2.1/revision/882

[1]: http://packetstormsecurity.com/files/127295/ocsinventoryng-xss.txt

Comment 1 Vasyl Kaigorodov 2014-07-08 09:33:25 UTC
Created ocsinventory tracking bugs for this issue:

Affects: fedora-all [bug 1117207]
Affects: epel-all [bug 1117208]

Comment 2 Vasyl Kaigorodov 2014-07-08 09:33:40 UTC
CVE request: http://seclists.org/bugtraq/2014/Jul/16

Comment 3 Fedora Update System 2014-07-19 06:00:10 UTC
ocsinventory-2.0.5-8.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2014-07-19 06:02:38 UTC
ocsinventory-2.0.5-8.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Product Security DevOps Team 2019-06-08 02:33:51 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.