Hide Forgot
== Issue 1 == === Summary === A flaw in the display of the branch field of a review request allows an attacker to inject arbitrary HTML, allowing attackers to construct scripts that run in the context of the page. === Affected Deployments === All Review Board deployments are vulnerable to this flaw. === Scope === Any registered user on a Review Board instance can provide malicious content for this field, impacting any user who views the page. === Resolution === The field's contents were set to HTML-escaped on display. === Acknowledgements === Frederik Braun from Mozilla is credited with discovering this vulnerability. Christian Hammond, lead upstream developer of Review Board, is credited with correcting it. == Issue 2 == === Summary === A flaw in the display of the alt text for an uploaded screenshot or image file attachment allows an attacker to inject arbitrary HTML through the caption field, allowing attackers to construct scripts that run in the context of the page. === Affected Deployments === All Review Board deployments are vulnerable to this flaw. === Scope === Any registered user on a Review Board instance can provide malicious content for a caption, impacting any user who views the page. === Resolution === The field's contents were set to HTML-escaped on display. === Acknowledgements === Frederik Braun from Mozilla is credited with discovering this vulnerability. Christian Hammond, lead upstream developer of Review Board, is credited with correcting it.
Fixed upstream in versions 1.6.21 and 1.7.17: http://www.reviewboard.org/news/2013/11/05/review-board-1-6-21-and-1-7-17-released/ http://www.reviewboard.org/docs/releasenotes/reviewboard/1.6.21/ http://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17/
ReviewBoard-1.7.17-1.fc20, python-djblets-0.7.23-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
ReviewBoard-1.7.18-1.fc19, python-djblets-0.7.23-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
ReviewBoard-1.7.18-1.fc18, python-djblets-0.7.23-1.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
ReviewBoard-1.7.18-1.el6, python-djblets-0.7.23-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.