oss-sec mailing list archives

Re: CVE-2023-37581: Apache Roller: XSS vulnerability for site with untrusted users


From: Srivani Reddy <srivani.reddy () securelayer7 net>
Date: Wed, 16 Aug 2023 03:45:35 +0000

Hi Dave,

Can you please change the name Srivani Reddy to our company SecureLayer7 Technologies Pvt Ltd as we submitted the 
vulnerability?

Regards,
Srivani


________________________________
From: Dave <snoopdave () gmail com>
Sent: Sunday, August 6, 2023 1:42:26 AM
To: Apache Security Team <security () apache org>; oss-security () lists openwall com <oss-security () lists openwall 
com>; Srivani Reddy <srivani.reddy () securelayer7 net>; dev () roller apache org <dev () roller apache org>; Roller 
User <user () roller apache org>
Subject: CVE-2023-37581: Apache Roller: XSS vulnerability for site with untrusted users


The Apache Roller project would like to announce a vulnerability that may impact Roller installations that allow group 
blogging with untrusted users.

Severity:

Medium (only impacts group blogging sites with untrusted users)

Description:

Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all 
versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack.

Mitigation:

If you are not running a group blog, then no mitigation is needed. If you are running a group blog and you do not have 
Roller configured for untrusted users, then you need to do nothing because you trust your users to author raw HTML and 
other web content.

But, if you are running a group blog and you do not trust your users to author HTML, CSS and JavaScript then you should 
upgrade to Roller 6.1.2 and you should disable Roller's File Upload feature. Roller 6.1.2 is available for download 
here: https://roller.apache.org/downloads/downloads.html

Apache Roller would like to thank Srivani Reddy for reporting this vulnerability.


This email and any files transmitted with it are confidential and intended solely for the use of the individual or 
entity to whom they are addressed. If you have received this email in error please notify the system manager. This 
message contains confidential information and is intended only for the individual named. If you are not the named 
addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if 
you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient 
you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this 
information is strictly prohibited.

Current thread: