Bug 1377396 (CVE-2016-7419, oC-SA-2016-011) - CVE-2016-7419 owncloud: Stored XSS in gallery application
Summary: CVE-2016-7419 owncloud: Stored XSS in gallery application
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2016-7419, oC-SA-2016-011
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1377397 1377398
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-09-19 14:54 UTC by Andrej Nemec
Modified: 2021-02-17 03:19 UTC (History)
4 users (show)

Fixed In Version: owncloud 9.0.52
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-09-19 15:33:48 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2016-09-19 14:54:36 UTC
Due to a recent migration of the Gallery app to the new sharing endpoint a parameter changed from an integer to a string value. This value wasn't sanitized before and was thus now vulnerable to a Cross-Site-Scripting attack.

To exploit this vulnerability an authenticated attacker has to share a folder with someone else, get them to open the shared folder in the Gallery app and open the sharing window there.

Since ownCloud employs a strict Content-Security-Policy this vulnerability is only exploitable in browsers not supporting Content-Security-Policy.

External References:

https://owncloud.org/security/advisory/?id=oc-sa-2016-011

Upstream fix:

https://github.com/owncloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc

References:

https://hackerone.com/reports/145355

Comment 1 Andrej Nemec 2016-09-19 14:55:21 UTC
Created owncloud tracking bugs for this issue:

Affects: fedora-all [bug 1377397]
Affects: epel-all [bug 1377398]

Comment 2 James Hogarth 2016-09-19 15:33:48 UTC
As per the tracking bugs, the current packages are at 9.0.4 and not affected by this.


Note You need to log in before you can comment on or make changes to this bug.