Bug 1850863 (CVE-2019-13127)

Summary: CVE-2019-13127 mxgraph: improper input validation leads to XSS
Product: [Other] Security Response Reporter: msiddiqu
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: c.david86, jamesturner246, jerboaa, lkundrak
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-06-25 05:20:23 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1850864, 1850865    
Bug Blocks:    

Description msiddiqu 2020-06-25 04:51:27 UTC
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.


Upstream commit: 

https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3

References:

https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-history
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txt

Comment 1 msiddiqu 2020-06-25 04:51:54 UTC
Created jgraphx tracking bugs for this issue:

Affects: epel-6 [bug 1850865]
Affects: fedora-all [bug 1850864]

Comment 2 Product Security DevOps Team 2020-06-25 05:20:23 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.