Bug 1436192 (CVE-2017-6958) - CVE-2017-6958 mantis: XSS in search page
Summary: CVE-2017-6958 mantis: XSS in search page
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2017-6958
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1436195 1436196
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-03-27 12:22 UTC by Martin Prpič
Modified: 2019-09-29 14:08 UTC (History)
1 user (show)

Fixed In Version: mantis 2.0.2
Clone Of:
Environment:
Last Closed: 2017-03-27 13:28:14 UTC
Embargoed:


Attachments (Terms of Use)

Description Martin Prpič 2017-03-27 12:22:08 UTC
The following issue was found in mantis:

A cross-site scripting (XSS) vulnerability in the MantisBT Source Integration plugin search result page allows remote attackers to inject arbitrary HTML or JavaScript (the latter, only if MantisBT's CSP settings permit it) by crafting any valid parameter.

References:

https://github.com/mantisbt-plugins/source-integration/issues/205
http://www.openwall.com/lists/oss-security/2017/03/17/2

Comment 1 Martin Prpič 2017-03-27 12:24:20 UTC
Patch for 1.3.x in:

https://www.mantisbt.org/bugs/view.php?id=22486

Comment 2 Martin Prpič 2017-03-27 12:26:32 UTC
Created mantis tracking bugs for this issue:

Affects: fedora-all [bug 1436195]
Affects: epel-5 [bug 1436196]

Comment 3 Gianluca Sforna 2017-03-27 13:20:09 UTC
So this is pretty weird, because it looks like a different CVE for the same upstream bug we discussed lately in bug #1431179.

I guess the resolution is also the same?

Comment 4 Martin Prpič 2017-03-27 13:28:14 UTC
(In reply to Gianluca Sforna from comment #3)
> So this is pretty weird, because it looks like a different CVE for the same
> upstream bug we discussed lately in bug #1431179.
> 
> I guess the resolution is also the same?

Ohh, I didn't even notice that the bug points to a different CVE. This one is specific to the 2.0.x branch it seems so I guess it's no-action for mantis in fedora/epel. Sorry for the noise!

"After verification, the issue does not seem to be reproducible in 1.x branch, first affected version is 2.0.0-beta.1. Setting target to 2.0.2."


Note You need to log in before you can comment on or make changes to this bug.