Fedora Account System
Red Hat Associate
Red Hat Customer
The following issue was found in mantis: A cross-site scripting (XSS) vulnerability in the MantisBT Source Integration plugin search result page allows remote attackers to inject arbitrary HTML or JavaScript (the latter, only if MantisBT's CSP settings permit it) by crafting any valid parameter. References: https://github.com/mantisbt-plugins/source-integration/issues/205 http://www.openwall.com/lists/oss-security/2017/03/17/2
Patch for 1.3.x in: https://www.mantisbt.org/bugs/view.php?id=22486
Created mantis tracking bugs for this issue: Affects: fedora-all [bug 1436195] Affects: epel-5 [bug 1436196]
So this is pretty weird, because it looks like a different CVE for the same upstream bug we discussed lately in bug #1431179. I guess the resolution is also the same?
(In reply to Gianluca Sforna from comment #3) > So this is pretty weird, because it looks like a different CVE for the same > upstream bug we discussed lately in bug #1431179. > > I guess the resolution is also the same? Ohh, I didn't even notice that the bug points to a different CVE. This one is specific to the 2.0.x branch it seems so I guess it's no-action for mantis in fedora/epel. Sorry for the noise! "After verification, the issue does not seem to be reproducible in 1.x branch, first affected version is 2.0.0-beta.1. Setting target to 2.0.2."