Bug 1063099 (CVE-2014-1869) - CVE-2014-1869 stapler-adjunct-zeroclipboard: multiple cross-site scripting (XSS) flaws
Summary: CVE-2014-1869 stapler-adjunct-zeroclipboard: multiple cross-site scripting (X...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2014-1869
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1063103
TreeView+ depends on / blocked
 
Reported: 2014-02-10 01:56 UTC by Murray McAllister
Modified: 2021-02-17 06:53 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-08 02:31:27 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:0070 0 normal SHIPPED_LIVE Important: Red Hat OpenShift Enterprise 3.1.1 bug fix and enhancement update 2016-01-27 00:12:41 UTC

Description Murray McAllister 2014-02-10 01:56:09 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-1869 to
the following vulnerability:

Name: CVE-2014-1869
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1869
Assigned: 20140206
Reference: https://github.com/zeroclipboard/zeroclipboard/commit/2f9eb9750a433965572d047e24b0fc78fd1415ca
Reference: https://github.com/zeroclipboard/zeroclipboard/pull/335
Reference: https://github.com/zeroclipboard/zeroclipboard/releases/tag/v1.3.2

Multiple cross-site scripting (XSS) vulnerabilities in
ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon
Rohan and James M. Greene, allow remote attackers to inject arbitrary
web script or HTML via vectors related to certain SWF query parameters
(aka loaderInfo.parameters).

Comment 1 Murray McAllister 2014-02-10 02:01:12 UTC
There is a stapler-adjunct-zeroclipboard jar in the Jenkins as shipped for OpenShift Enterprise

Comment 4 Kurt Seifried 2014-08-05 05:36:51 UTC
Statement:

This issue affects the versions of Jenkins as shipped with Red Hat OpenShift Enterprise 1 and 2. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Comment 6 Ján Rusnačko 2015-10-23 14:06:38 UTC
Kurt, 

I am making your Comment 5 private, because that statement is picked up in favor of the one from Comment 4 and is showing up on CVE pages. I am doing that because statement in comment 5 contains typo (Jnekins), refers to non-existing product (Red Hat OpenShift Enterprise Linux 2) and in general says the same thing as the one from comment 4.

Comment 8 errata-xmlrpc 2016-01-26 19:14:00 UTC
This issue has been addressed in the following products:

  RHEL 7 Version of OpenShift Enterprise 3.1

Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070


Note You need to log in before you can comment on or make changes to this bug.