User-Agent: Mozilla/5.0 (X11; Linux i686; rv:2.0b8pre) Gecko/20101029 Firefox/4.0b8pre Pootle allows XSS on the match_names parameter when searching for matching check failures. Reproducible: Always Steps to Reproduce: 1. Run this URL https://localize.mozilla.org/te/bugzilla_components/translate.html?match_names=check-isfuzzy,untranslated,%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E&view_mode=review Actual Results: XSS possible Expected Results: No XSS vulnerabilty
This is fixed upstream for 2.1: http://translate.svn.sourceforge.net/viewvc/translate/src/branches/Pootle-2.1/local_apps/pootle_store/views.py?r1=16167&r2=16166&pathrev=16167 This will be fixed with upstreams release of 2.1.2 bug fix release.
I see that 2.1.2 is now available: http://sourceforge.net/projects/translate/files/Pootle/2.1.2/ But the README.txt there does not mention this security flaw. Requesting clarification on whether we can make this bug public and get updates into Fedora.
Sorry, RELEASE.txt.
RELEASE.txt contains: This release includes an important security fix to a cross site scripting vulnerability in the translate page. All users are encouraged to upgrade immediately. Fedora updates are submitted already, making this public so this bug can be added to the bodhi update request.
pootle-2.1.2-1.fc14 has been submitted as an update for Fedora 14. https://admin.fedoraproject.org/updates/pootle-2.1.2-1.fc14
pootle-2.1.2-1.el5 has been submitted as an update for Fedora EPEL 5. https://admin.fedoraproject.org/updates/pootle-2.1.2-1.el5
pootle-2.1.2-1.fc13 has been submitted as an update for Fedora 13. https://admin.fedoraproject.org/updates/pootle-2.1.2-1.fc13
pootle-2.1.2-1.fc12 has been submitted as an update for Fedora 12. https://admin.fedoraproject.org/updates/pootle-2.1.2-1.fc12
pootle-2.1.2-1.fc12 has been pushed to the Fedora 12 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update pootle'. You can provide feedback for this update here: https://admin.fedoraproject.org/updates/pootle-2.1.2-1.fc12
pootle-2.1.2-1.fc14 has been pushed to the Fedora 14 stable repository. If problems still persist, please make note of it in this bug report.
pootle-2.1.2-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
pootle-2.1.2-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
pootle-2.1.2-1.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
This issue was assigned the name CVE-2010-4245.