Bug 1811998 (CVE-2019-3686)

Summary: CVE-2019-3686 openqa: XSS in the distri and version parameter leeds to remote code execution
Product: [Other] Security Response Reporter: Michael Kaplan <mkaplan>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: awilliam
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-03-10 15:10:31 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1811999    
Bug Blocks:    

Description Michael Kaplan 2020-03-10 11:14:46 UTC
There is an XSS in openqa in the distri and version parameter which could leed to a remote code execution and information leak.

Comment 1 Michael Kaplan 2020-03-10 11:15:03 UTC
Created openqa tracking bugs for this issue:

Affects: fedora-all [bug 1811999]

Comment 2 Michael Kaplan 2020-03-10 11:15:42 UTC
Suse Reference:

https://bugzilla.suse.com/show_bug.cgi?id=1142849

Comment 3 Adam Williamson 2020-03-10 15:10:31 UTC
Thanks, but I fixed this six months ago :)

https://bugzilla.suse.com/show_bug.cgi?id=1142849#c3

All stable releases are on upstream snapshots with the fix for this (and for a similar issue in comments that was fixed shortly afterwards) already included - yes, even F30, which is a bit behind the other branches, it's on an early August snapshot from shortly after the fix for this landed. before that I had it backported (it was https://github.com/os-autoinst/openQA/pull/2213 ).