Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1063099 - (CVE-2014-1869) CVE-2014-1869 stapler-adjunct-zeroclipboard: multiple cross-site scripting (XSS) flaws
CVE-2014-1869 stapler-adjunct-zeroclipboard: multiple cross-site scripting (X...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140131,repor...
: Reopened, Security
Depends On:
Blocks: 1063103
  Show dependency treegraph
 
Reported: 2014-02-09 20:56 EST by Murray McAllister
Modified: 2018-02-15 09:11 EST (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-08-05 01:36:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:0070 normal SHIPPED_LIVE Important: Red Hat OpenShift Enterprise 3.1.1 bug fix and enhancement update 2016-01-26 19:12:41 EST

  None (edit)
Description Murray McAllister 2014-02-09 20:56:09 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-1869 to
the following vulnerability:

Name: CVE-2014-1869
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1869
Assigned: 20140206
Reference: https://github.com/zeroclipboard/zeroclipboard/commit/2f9eb9750a433965572d047e24b0fc78fd1415ca
Reference: https://github.com/zeroclipboard/zeroclipboard/pull/335
Reference: https://github.com/zeroclipboard/zeroclipboard/releases/tag/v1.3.2

Multiple cross-site scripting (XSS) vulnerabilities in
ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon
Rohan and James M. Greene, allow remote attackers to inject arbitrary
web script or HTML via vectors related to certain SWF query parameters
(aka loaderInfo.parameters).
Comment 1 Murray McAllister 2014-02-09 21:01:12 EST
There is a stapler-adjunct-zeroclipboard jar in the Jenkins as shipped for OpenShift Enterprise
Comment 4 Kurt Seifried 2014-08-05 01:36:51 EDT
Statement:

This issue affects the versions of Jenkins as shipped with Red Hat OpenShift Enterprise 1 and 2. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Comment 6 Ján Rusnačko 2015-10-23 10:06:38 EDT
Kurt, 

I am making your Comment 5 private, because that statement is picked up in favor of the one from Comment 4 and is showing up on CVE pages. I am doing that because statement in comment 5 contains typo (Jnekins), refers to non-existing product (Red Hat OpenShift Enterprise Linux 2) and in general says the same thing as the one from comment 4.
Comment 8 errata-xmlrpc 2016-01-26 14:14:00 EST
This issue has been addressed in the following products:

  RHEL 7 Version of OpenShift Enterprise 3.1

Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070

Note You need to log in before you can comment on or make changes to this bug.