Bug 1439819 (CVE-2017-2674) - CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
Summary: CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2017-2674
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1438631 1439826 1447756
TreeView+ depends on / blocked
 
Reported: 2017-04-06 15:02 UTC by Adam Mariš
Modified: 2021-02-17 02:22 UTC (History)
13 users (show)

Fixed In Version: BPMS 6.4.3, BRMS 6.4.3
Doc Type: Bug Fix
Doc Text:
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.
Clone Of:
Environment:
Last Closed: 2017-05-10 00:30:46 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1217 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss BRMS security update 2017-05-09 21:13:24 UTC
Red Hat Product Errata RHSA-2017:1218 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss BPM Suite security update 2017-05-09 21:13:04 UTC

Description Adam Mariš 2017-04-06 15:02:46 UTC
It was found that Task Filter List in business central accepts HTML tags in the Name field. When creating a new task filtered list with crafted Name field and deleting it, HTML code is rendered.

Upstream bug:

https://issues.jboss.org/browse/RHBPMS-4625

Comment 3 Pavel Polischouk 2017-05-08 14:57:34 UTC
Acknowledgments:

Name: Chris Hebert, Vikas Pandey, Harold Schliesske, Ryan Stanley (Noblis)

Comment 4 errata-xmlrpc 2017-05-09 17:14:39 UTC
This issue has been addressed in the following products:

  Red Hat JBoss BPM Suite 6.4.3

Via RHSA-2017:1218 https://access.redhat.com/errata/RHSA-2017:1218

Comment 5 errata-xmlrpc 2017-05-09 17:14:58 UTC
This issue has been addressed in the following products:

  Red Hat JBoss BRMS 6.4.3

Via RHSA-2017:1217 https://access.redhat.com/errata/RHSA-2017:1217


Note You need to log in before you can comment on or make changes to this bug.