Fedora Account System
Red Hat Associate
Red Hat Customer
It was found that Pagure served uploaded files from its attachment endpoint with content types that instructed the browser to parse HTML files, which could lead to Cross-Site Scripting attacks. Upstream patch: https://pagure.io/pagure/c/8b231cd378cf880df3bf7cd81277c1f771dab988 The release that fixes this issue is Pagure 2.3.4.
Created pagure tracking bugs for this issue: Affects: fedora-all [bug 1360628] Affects: epel-7 [bug 1360629]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.