Bug 780296 (SOA-2698) - CVE-2010-3878 EAP jmx-console CSRF
Summary: CVE-2010-3878 EAP jmx-console CSRF
Keywords:
Status: CLOSED WONTFIX
Alias: SOA-2698
Product: JBoss Enterprise SOA Platform 5
Classification: JBoss
Component: Documentation
Version: 5.0.2
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: 5.2.0 GA
Assignee: David Le Sage
QA Contact:
URL: http://jira.jboss.org/jira/browse/SOA...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-12-17 12:31 UTC by Marc Schoenefeld
Modified: 2014-05-27 01:30 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-11-15 17:07:27 UTC
Type: Bug


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SOA-2698 0 None None None Never

Description Marc Schoenefeld 2010-12-17 12:31:16 UTC
Affects: Release Notes
project_key: SOA

Fix CVE-2010-3878 , patch available via JBPAPP-4719 , impact=low to moderate

Comment 1 Darran Lofthouse 2010-12-17 13:07:13 UTC
The 5.0.3 release is not a valid release, moving to unscheduled to allow for normal triage.

Comment 2 Marc Schoenefeld 2010-12-17 14:02:48 UTC
To fix manually , for each used profile

1) open server/{profile}/deploy/management/console-mgr/jboss-service.xml

2) comment the "org.jboss.console.manager.DeploymentFileRepository" mbean. 
...
   <!--
   <mbean code="org.jboss.console.manager.DeploymentFileRepository"
      name="jboss.admin:service=DeploymentFileRepository">
      <attribute name="BaseDir">./deploy/management</attribute>
   </mbean>
   -->

3) save server/{profile}/deploy/management/console-mgr/jboss-service.xml


Comment 3 Anne-Louise Tangring 2010-12-21 18:22:59 UTC
This should be documented for SOA 5.1.0

Comment 4 Dana Mison 2011-01-04 05:47:41 UTC
Affects: Added: [Release Notes]


Comment 6 Dana Mison 2011-01-05 00:12:13 UTC
Writer: Added: Darrin


Comment 7 Dana Mison 2011-01-27 10:25:52 UTC
Not sure exactly what to document here as the issue has been resolved in EAP - just release note for resolution ?

Comment 8 David Le Sage 2011-07-21 00:03:43 UTC
Release Notes Docs Status: Added: Not Required
Writer: Removed: Darrin Added: dlesage


Comment 9 David Le Sage 2011-07-21 00:04:37 UTC
Marked as out of date as fixed upstream as per Darrin's comment.  Please reopen if it does need work.


Note You need to log in before you can comment on or make changes to this bug.