Bug 1373344 (CVE-2016-7033)
| Summary: | CVE-2016-7033 JBoss bpms: stored XSS in dashbuilder | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Jeremy Choi <jechoi> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | alazarot, dgutierr, ed.tirelli, etirelli, jcoleman, kris.verlaenen, kverlaen, lpetrovi, mbaluch, mwinkler, nwallace, pavelp, rrajasek, rzhang, tkirby |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: |
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via dashbuilder. Remote, authenticated attackers that have privileges to access dashbuilder (usually admins) can store scripts in several editable fields, which are not properly sanitized before showing to other users, including other admins.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-02-06 19:42:25 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1373338, 1412839 | ||
|
Description
Jeremy Choi
2016-09-06 04:26:50 UTC
Acknowledgments: Name: Jeremy Choi (Red Hat Product Security Team) This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.4.1 Via RHSA-2017:0249 https://rhn.redhat.com/errata/RHSA-2017-0249.html |