Bug 793518 (JBEPP-598) - XSS issue in user creation page
Summary: XSS issue in user creation page
Keywords:
Status: CLOSED NEXTRELEASE
Alias: JBEPP-598
Product: JBoss Enterprise Portal Platform 5
Classification: JBoss
Component: unspecified
Version: 5.1.0.ER03
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: 5.1.1.DEV01
Assignee: hfnukal@redhat.com
QA Contact:
URL: http://jira.jboss.org/jira/browse/JBE...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-10-29 15:22 UTC by Viliam Rockai
Modified: 2015-09-01 03:31 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-04-19 14:55:49 UTC
Type: Bug


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 793840 0 high CLOSED XSS issues with user's firstname and lastname 2021-02-22 00:41:40 UTC
Red Hat Issue Tracker JBEPP-598 0 Major Closed XSS issue in user creation page 2012-08-23 07:00:33 UTC

Internal Links: 793840

Description Viliam Rockai 2010-10-29 15:22:24 UTC
project_key: JBEPP

when creating new user (even through register form without logging in!), you can put XSS string "<script>alert('hi');</script>" as his first/last name. while browsing (Searching) users, the script is invoked.

the string can be put into all user attributes (street, town and so on) and this may cause some troubles in the future if there will be some sort of user browser showing those fields...

Comment 1 Thomas Heute 2010-11-01 16:14:22 UTC
Link: Added: This issue is related to GTNPORTAL-1616


Comment 2 Thomas Heute 2010-11-12 08:43:26 UTC
Tentatively set for 5.1.0 CR01

Comment 3 Thomas Heute 2010-11-12 12:27:06 UTC
Release Notes Docs Status: Removed: Not Required Added: Documented as Known Issue


Comment 7 hfnukal@redhat.com 2011-04-19 14:55:49 UTC
Release Notes Docs Status: Removed: Documented as Known Issue Added: Not Yet Documented
Release Notes Text: Added: Javascript is not executed in list, if entered to fields


Comment 8 Michal Vanco 2011-05-03 11:24:07 UTC
Link: Added: This issue relates to JBEPP-914


Comment 9 Scott Mumford 2011-07-11 01:36:41 UTC
Release Notes Docs Status: Removed: Not Yet Documented Added: Documented as Resolved Issue
Release Notes Text: Removed: Javascript is not executed in list, if entered to fields Added: Security vulnerabilies arising from the execution of XSS javascript entered into various portal form fields have been eradicated in this release.

The resolution to this issue also resolves the following related JIRA issues:
https://issues.jboss.org/browse/JBEPP-847
https://issues.jboss.org/browse/JBEPP-997


Comment 10 Scott Mumford 2011-08-22 02:52:43 UTC
Marked as 'Release Note Not Required" to prevent this JIRA being extracted in dynamic Release Note biulds.
The above Release Note text has been included in a static section of the document.

Comment 11 Scott Mumford 2011-08-22 02:52:43 UTC
Release Notes Docs Status: Removed: Documented as Resolved Issue Added: Not Required
Release Notes Text: Removed: Security vulnerabilies arising from the execution of XSS javascript entered into various portal form fields have been eradicated in this release.

The resolution to this issue also resolves the following related JIRA issues:
https://issues.jboss.org/browse/JBEPP-847
https://issues.jboss.org/browse/JBEPP-997 Added:     This release of JBoss Enterprise Portal Platform resolves a number of Cross Site Scripting found in the user creation and new page creation forms.

    The following issues have been resolved:
    https://issues.jboss.org/browse/JBEPP-365
    https://issues.jboss.org/browse/JBEPP-598
    https://issues.jboss.org/browse/JBEPP-595
    https://issues.jboss.org/browse/JBEPP-847
    https://issues.jboss.org/browse/JBEPP-997
    https://issues.jboss.org/browse/JBEPP-914

    Work to address further XSS issues is ongoing. 


Comment 12 Scott Mumford 2011-08-22 02:53:35 UTC
Release Notes Text: Removed:     This release of JBoss Enterprise Portal Platform resolves a number of Cross Site Scripting found in the user creation and new page creation forms.

    The following issues have been resolved:
    https://issues.jboss.org/browse/JBEPP-365
    https://issues.jboss.org/browse/JBEPP-598
    https://issues.jboss.org/browse/JBEPP-595
    https://issues.jboss.org/browse/JBEPP-847
    https://issues.jboss.org/browse/JBEPP-997
    https://issues.jboss.org/browse/JBEPP-914

    Work to address further XSS issues is ongoing.  Added:     This release of JBoss Enterprise Portal Platform resolves a number of Cross Site Scripting issues found in the user creation and new page creation forms.

    The following issues have been resolved:
    https://issues.jboss.org/browse/JBEPP-365
    https://issues.jboss.org/browse/JBEPP-598
    https://issues.jboss.org/browse/JBEPP-595
    https://issues.jboss.org/browse/JBEPP-847
    https://issues.jboss.org/browse/JBEPP-997
    https://issues.jboss.org/browse/JBEPP-914

    Work to address further XSS issues is ongoing. 


Comment 13 hfnukal@redhat.com 2011-09-07 16:19:05 UTC
Security: Removed: RHT+eXo Added: Public



Note You need to log in before you can comment on or make changes to this bug.