Bug 1950906 - [RFE] XSS Vulnerability with Noobaa version 5.5.0-3bacc6b
Summary: [RFE] XSS Vulnerability with Noobaa version 5.5.0-3bacc6b
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenShift Container Storage
Classification: Red Hat Storage
Component: Multi-Cloud Object Gateway
Version: 4.6
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ---
: OCS 4.7.1
Assignee: Nimrod Becker
QA Contact: Filip Balák
URL:
Whiteboard:
Depends On: 1943388 1950915
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-04-19 06:27 UTC by Nimrod Becker
Modified: 2021-06-15 16:50 UTC (History)
10 users (show)

Fixed In Version: 4.7.1-403.ci
Doc Type: No Doc Update
Doc Text:
Clone Of: 1943388
Environment:
Last Closed: 2021-06-15 16:50:37 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github noobaa noobaa-core pull 6531 0 None open Backport to 5.7 2021-05-25 16:25:41 UTC
Red Hat Product Errata RHBA-2021:2449 0 None None None 2021-06-15 16:50:53 UTC

Comment 5 Elad 2021-05-26 09:00:40 UTC
Verification to be based on regression testing only - https://bugzilla.redhat.com/show_bug.cgi?id=1950915#c5

Comment 12 Filip Balák 2021-06-02 12:11:54 UTC
As Eran wrote in https://bugzilla.redhat.com/show_bug.cgi?id=1943388#c17, the vulnerability is not exploitable with provided payload because browsers encode the url. The issue was reproduced on OCS 4.5.2-146.ci. Used payload in browser before the fix can be seen in attachment 1787610 [details] from BZ 1950915. The url is not rendered in error page anymore after the fix as seen in attachment 1787611 [details] from BZ 1950915 (the page after the fix looks the same for this version). Removing url from error page body prevents attacks related to this BZ. --> VERIFIED

Tested with:
ocs-operator.v4.7.1-403.ci

Comment 17 errata-xmlrpc 2021-06-15 16:50:37 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Red Hat OpenShift Container Storage 4.7.1 bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:2449


Note You need to log in before you can comment on or make changes to this bug.