Bug 1813969 (CVE-2020-8823)
| Summary: | CVE-2020-8823 sockJS: function htmlfile is not checking the non-alphanumeric symbols which could result in reflected XSS | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Michael Kaplan <mkaplan> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | abonas, avibelli, bgeorges, chazlett, dbaker, dkreling, gbrown, jbalunas, jpallich, jwon, kconner, krathod, lnacshon, lthon, mcooper, mszynkie, pgallagh, python-sig, rcernich, rosser.bjr, rruss, sisharma |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | sockjs 0.3.1 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A cross-site scripting (XSS) vulnerability was found in the Node.js library, sockjs. An attacker could use this vulnerability to supply a query string with script tags, which could trick a victim into executing a specially crafted JavaScript code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-03-19 22:31:43 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1813979 | ||
| Bug Blocks: | 1814173 | ||
|
Description
Michael Kaplan
2020-03-16 15:29:45 UTC
External References: https://github.com/theyiyibest/Reflected-XSS-on-SockJS Created python-sockjs-tornado tracking bugs for this issue: Affects: fedora-all [bug 1813979] Upstream commit: https://github.com/sockjs/sockjs-node/commit/8f64d46c02d96b46357827216143c43b236edd36 ServiceMesh packages sockjs in the following components: - servicemesh-grafana - jaeger - kiali However, all components use at least 0.3.18+ and are not vulnerable to the XSS flaw. Jaeger v1.17.0 is also not vulnerable, packaging v0.3.19 of sockjs. This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-8823 |