Bug 1433087 (CVE-2017-2658)

Summary: CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
Product: [Other] Security Response Reporter: Pavel Polischouk <pavelp>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: alazarot, etirelli, jcoleman, jolee, kverlaen, lpetrovi, mbaluch, mwinkler, nwallace, rrajasek, rzhang, tkirby, vhalbert
Target Milestone: ---Keywords: Reopened, Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
It was discovered that the Dashbuilder login page could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 03:09:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1469740, 1469741    
Bug Blocks: 1429673, 1433086    

Description Pavel Polischouk 2017-03-16 18:33:09 UTC
It was discovered that the Dashbuilder login page could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).

Comment 1 Pavel Polischouk 2017-03-16 18:35:09 UTC
Acknowledgments:

Name: Martin Weiler (Red Hat)

Comment 3 errata-xmlrpc 2017-03-16 21:10:18 UTC
This issue has been addressed in the following products:

  Red Hat JBoss BPM Suite 6.4.2

Via RHSA-2017:0557 https://rhn.redhat.com/errata/RHSA-2017-0557.html

Comment 7 errata-xmlrpc 2018-07-23 19:35:22 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Data Virtualization

Via RHSA-2018:2243 https://access.redhat.com/errata/RHSA-2018:2243