oss-sec mailing list archives
Re: CVE-2023-37581: Apache Roller: XSS vulnerability for site with untrusted users
From: Srivani Reddy <srivani.reddy () securelayer7 net>
Date: Wed, 16 Aug 2023 03:45:35 +0000
Hi Dave, Can you please change the name Srivani Reddy to our company SecureLayer7 Technologies Pvt Ltd as we submitted the vulnerability? Regards, Srivani ________________________________ From: Dave <snoopdave () gmail com> Sent: Sunday, August 6, 2023 1:42:26 AM To: Apache Security Team <security () apache org>; oss-security () lists openwall com <oss-security () lists openwall com>; Srivani Reddy <srivani.reddy () securelayer7 net>; dev () roller apache org <dev () roller apache org>; Roller User <user () roller apache org> Subject: CVE-2023-37581: Apache Roller: XSS vulnerability for site with untrusted users The Apache Roller project would like to announce a vulnerability that may impact Roller installations that allow group blogging with untrusted users. Severity: Medium (only impacts group blogging sites with untrusted users) Description: Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: If you are not running a group blog, then no mitigation is needed. If you are running a group blog and you do not have Roller configured for untrusted users, then you need to do nothing because you trust your users to author raw HTML and other web content. But, if you are running a group blog and you do not trust your users to author HTML, CSS and JavaScript then you should upgrade to Roller 6.1.2 and you should disable Roller's File Upload feature. Roller 6.1.2 is available for download here: https://roller.apache.org/downloads/downloads.html Apache Roller would like to thank Srivani Reddy for reporting this vulnerability. This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited.
Current thread:
- CVE-2023-37581: Apache Roller: XSS vulnerability for site with untrusted users Dave (Aug 05)
- Re: CVE-2023-37581: Apache Roller: XSS vulnerability for site with untrusted users Srivani Reddy (Aug 16)