Bug 1255170 - (CVE-2015-5216) CVE-2015-5216 ipsilon: XSS due to exception handling
CVE-2015-5216 ipsilon: XSS due to exception handling
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 1255176 1255775
Blocks: 1255174
  Show dependency treegraph
Reported: 2015-08-19 16:25 EDT by Kurt Seifried
Modified: 2016-11-08 11:21 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A flaw was discovered in the Ipsilon IdP server in its use of Python templates, where JavaScript code could potentially be injected into an Python exception-message template. A remote, unauthorised attacker could use this flaw to perform an XXS attack.
Story Points: ---
Clone Of:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Kurt Seifried 2015-08-19 16:25:35 EDT
Michael Scherer of Red Hat reports:

ipsilon does not escape HTML when processing http(s) request responses, allowing to inject js code into Python exception message template.

Upstream patch:

Comment 1 Kurt Seifried 2015-08-19 16:36:03 EDT
Created ipsilon tracking bugs for this issue:

Affects: fedora-all [bug 1255176]
Comment 3 Viliam Križan 2015-08-24 04:58:49 EDT

This issue was discovered by Michael Scherer of Red Hat.
Comment 5 Ilya Etingof 2015-08-24 05:19:38 EDT

It was found that js code could potentially be injected into Python exception message template.

Note You need to log in before you can comment on or make changes to this bug.