Bug 1532122 (CVE-2017-17837)
Summary: | CVE-2017-17837 Apache DeltaSpike: XSS injection vulnerability in windowId handling | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sam Fowler <sfowler> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aileenc, alazarot, anstephe, apevec, chazlett, chrisw, etirelli, gvarsami, ibek, java-sig-commits, jcoleman, jjoyce, jolee, jschluet, jstastny, kbasil, kconner, kverlaen, ldimaggi, lef, lhh, lpeer, lpetrovi, markmc, mburns, mkolesni, nwallace, paradhya, puntogil, rbryant, rrajasek, rsynek, rwagner, rzhang, sclewis, sdaley, slinaber, tcunning, tdecacqu, tkirby, vhalbert |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | deltaspike 1.8.1 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 03:36:18 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1532123 | ||
Bug Blocks: | 1532124 |
Description
Sam Fowler
2018-01-08 03:53:31 UTC
Created deltaspike tracking bugs for this issue: Affects: fedora-all [bug 1532123] The Apache DeltaSpike JSF module is not included in OpenDaylight nor are there any calls to windowId. Moderate issues in Developer Studio won't be fixed. JBoss Developer Studio 11 uses patched version 1.8.1. |