Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1203190 - (CVE-2014-6393) CVE-2014-6393 express: cross-site scripting via content-type header
CVE-2014-6393 express: cross-site scripting via content-type header
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20150315,repor...
: Security
Depends On: 1203192 1203191
Blocks: 1203193
  Show dependency treegraph
 
Reported: 2015-03-18 07:31 EDT by Martin Prpič
Modified: 2015-04-30 09:08 EDT (History)
12 users (show)

See Also:
Fixed In Version: express 3.11, express 4.5
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-04-30 09:08:57 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2015-03-18 07:31:35 EDT
The following flaw was found in Express:

Vulnerable versions of express do not specify a charset field in the content-type heade while displaying 400 level response messages. The lack of enforcing user's browser to set correct charset, could be leveraged by an attacker to perform a cross-site scripting attack, using non-standard encodings, like UTF-7.

This flaw is fixed in version 3.11 and 4.5 of Express.

External References:

https://nodesecurity.io/advisories/express-no-charset-in-content-type-header
Comment 1 Martin Prpič 2015-03-18 07:33:07 EDT
Created nodejs-express tracking bugs for this issue:

Affects: fedora-all [bug 1203191]
Affects: epel-6 [bug 1203192]

Note You need to log in before you can comment on or make changes to this bug.