Bug 1638551
Summary: | CVE-2018-9206 js-jquery-file-upload: Unauthenticated arbitrary file upload [fedora-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Pedro Sampaio <psampaio> |
Component: | js-jquery-file-upload | Assignee: | Randy Barlow <rbarlow> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 28 | CC: | rbarlow |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Release Note | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2018-10-13 14:23:24 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1638549 |
Description
Pedro Sampaio
2018-10-11 21:24:32 UTC
Use the following template to for the 'fedpkg update' request to submit an update for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all associated bugs get updated when new packages are pushed to stable. ===== # bugfix, security, enhancement, newpackage (required) type=security # testing, stable request=testing # Bug numbers: 1234,9876 bugs=1638549,1638551 # Description of your update notes=Security fix for [PUT CVEs HERE] # Enable request automation based on the stable/unstable karma thresholds autokarma=True stable_karma=3 unstable_karma=-3 # Automatically close bugs when this marked as stable close_bugs=True # Suggest that users restart after update suggest_reboot=False ====== Additionally, you may opt to use the bodhi web interface to submit updates: https://bodhi.fedoraproject.org/updates/new Fedora does not ship anything from the server/ source folder, so is not affected by this: $ rpm -q --filesbypkg js-jquery-file-upload-9.22.0-1.fc29.noarch js-jquery-file-upload /usr/share/doc/js-jquery-file-upload js-jquery-file-upload /usr/share/doc/js-jquery-file-upload/CONTRIBUTING.md js-jquery-file-upload /usr/share/doc/js-jquery-file-upload/README.md js-jquery-file-upload /usr/share/licenses/js-jquery-file-upload js-jquery-file-upload /usr/share/licenses/js-jquery-file-upload/LICENSE.txt js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/angularjs.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/basic-plus.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/basic.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/cors js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/cors/postmessage.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/cors/result.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/jquery-ui-demo-ie8.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/jquery-ui-demo.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/jquery.fileupload-noscript.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/jquery.fileupload-ui-noscript.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/jquery.fileupload-ui.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/jquery.fileupload.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/css/style.css js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/img js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/img/loading.gif js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/img/progressbar.gif js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/index.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/jquery-ui.html js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/app.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/cors js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/cors/jquery.postmessage-transport.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/cors/jquery.xdr-transport.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-angular.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-audio.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-image.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-jquery-ui.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-process.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-ui.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-validate.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload-video.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.fileupload.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/jquery.iframe-transport.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/main.js js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/vendor js-jquery-file-upload /usr/share/web-assets/jQuery-File-Upload/js/vendor/jquery.ui.widget.js |