Bug 1436192 (CVE-2017-6958)

Summary: CVE-2017-6958 mantis: XSS in search page
Product: [Other] Security Response Reporter: Martin Prpič <mprpic>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: giallu
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mantis 2.0.2 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-03-27 13:28:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1436195, 1436196    
Bug Blocks:    

Description Martin Prpič 2017-03-27 12:22:08 UTC
The following issue was found in mantis:

A cross-site scripting (XSS) vulnerability in the MantisBT Source Integration plugin search result page allows remote attackers to inject arbitrary HTML or JavaScript (the latter, only if MantisBT's CSP settings permit it) by crafting any valid parameter.

References:

https://github.com/mantisbt-plugins/source-integration/issues/205
http://www.openwall.com/lists/oss-security/2017/03/17/2

Comment 1 Martin Prpič 2017-03-27 12:24:20 UTC
Patch for 1.3.x in:

https://www.mantisbt.org/bugs/view.php?id=22486

Comment 2 Martin Prpič 2017-03-27 12:26:32 UTC
Created mantis tracking bugs for this issue:

Affects: fedora-all [bug 1436195]
Affects: epel-5 [bug 1436196]

Comment 3 Gianluca Sforna 2017-03-27 13:20:09 UTC
So this is pretty weird, because it looks like a different CVE for the same upstream bug we discussed lately in bug #1431179.

I guess the resolution is also the same?

Comment 4 Martin Prpič 2017-03-27 13:28:14 UTC
(In reply to Gianluca Sforna from comment #3)
> So this is pretty weird, because it looks like a different CVE for the same
> upstream bug we discussed lately in bug #1431179.
> 
> I guess the resolution is also the same?

Ohh, I didn't even notice that the bug points to a different CVE. This one is specific to the 2.0.x branch it seems so I guess it's no-action for mantis in fedora/epel. Sorry for the noise!

"After verification, the issue does not seem to be reproducible in 1.x branch, first affected version is 2.0.0-beta.1. Setting target to 2.0.2."