Fedora Account System
Red Hat Associate
Red Hat Customer
Verification to be based on regression testing only - https://bugzilla.redhat.com/show_bug.cgi?id=1950915#c5
As Eran wrote in https://bugzilla.redhat.com/show_bug.cgi?id=1943388#c17, the vulnerability is not exploitable with provided payload because browsers encode the url. The issue was reproduced on OCS 4.5.2-146.ci. Used payload in browser before the fix can be seen in attachment 1787610 [details] from BZ 1950915. The url is not rendered in error page anymore after the fix as seen in attachment 1787611 [details] from BZ 1950915 (the page after the fix looks the same for this version). Removing url from error page body prevents attacks related to this BZ. --> VERIFIED Tested with: ocs-operator.v4.7.1-403.ci
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Red Hat OpenShift Container Storage 4.7.1 bug fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2021:2449