Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1144212 - (CVE-2014-3650) CVE-2014-3650 JBoss AeroGear: stored XSS via deviceToken
CVE-2014-3650 JBoss AeroGear: stored XSS via deviceToken
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20141024,repor...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-09-18 23:04 EDT by Trevor Jay
Modified: 2014-11-05 08:19 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-10-24 01:14:19 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Trevor Jay 2014-09-18 23:04:14 EDT
The user supplied deviceToken needs XSS protection. By issuing a malicious request an attacker can make visiting the /installations/ page result in a complete application compromise (as these pages have permission to issue all available REST calls). This is by simply having the entry pulled up, the victim doesn't have to "expand" it or otherwise interact with the installation entry to trigger the payload.
Comment 1 Arun Babu Neelicattu 2014-09-29 01:25:54 EDT
Upstream Issue:

https://issues.jboss.org/browse/AEROGEAR-1513
Comment 2 Trevor Jay 2014-09-29 01:44:56 EDT
Statement:

Not Vulnerable. Aerogear is not provided by any Red Hat product.
Comment 3 Trevor Jay 2014-10-23 23:28:54 EDT
As reported by Jan Rusnacko, this same flaw effect almost all of the account management fields: Email, Last Name, First, Name. That vector is not quite as serious (as it requires auth) but has been noted in this additional upstream issue:

https://issues.jboss.org/browse/AGPUSH-1082
Comment 4 Arun Babu Neelicattu 2014-10-24 01:13:10 EDT
Acknowledgements:

This issue was discovered by Jan Rusnacko and Trevor Jay of Red Hat Product Security.
Comment 5 Martin Prpič 2014-11-05 08:19:06 EST
IssueDescription:

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.

Note You need to log in before you can comment on or make changes to this bug.