A stored XSS was found in ovirt-engine 4.2.1.1 in the snapshot's description and comment.
Hi Pedro, I'm the engineering manager of the RHV Storage team, which should probably take ownership of this BZ. There's not to much to go on here (I'm guessing it's something like "create a snapshot with a description that contains javascript"). Can you provide more formal steps? Or perhaps they are in the blocked bug I don't have access to - could you add me as a CC there? Thanks! P.S. Adding the "Regression" keyword. This issue was reproduced with the above steps in 4.2, but not in the latest 4.1.z.
(In reply to Allon Mureinik from comment #1) > I'm the engineering manager of the RHV Storage team, which should probably > take ownership of this BZ. > There's not to much to go on here (I'm guessing it's something like "create > a snapshot with a description that contains javascript"). > Can you provide more formal steps? Or perhaps they are in the blocked bug I > don't have access to - could you add me as a CC there? Hi Allon, The details are recorded in product bug 1540925, which awels@ owns. It seems the issue is not specific to Storage but affects various fields in Ovirt front-end.
(In reply to Doran Moppert from comment #2) > (In reply to Allon Mureinik from comment #1) > > I'm the engineering manager of the RHV Storage team, which should probably > > take ownership of this BZ. > > There's not to much to go on here (I'm guessing it's something like "create > > a snapshot with a description that contains javascript"). > > Can you provide more formal steps? Or perhaps they are in the blocked bug I > > don't have access to - could you add me as a CC there? > > Hi Allon, > > The details are recorded in product bug 1540925, which awels@ owns. It > seems the issue is not specific to Storage but affects various fields in > Ovirt front-end. Thanks Doran. I was alerted to this issue when Yaniv Kaul added me to the CC list. Looking through bug 1540925 it seems that Alexander has things under control. Alexander/Doran/Pedro - If you need anything from my side, just let me know.
Acknowledgments: Name: Han Han (Red Hat)
External References: https://gerrit.ovirt.org/#/c/87265