Fwd: [CVE-2019-0234] Reflected Cross-site Scripting (XSS) Vulnerability
Naren <[email protected]> Mon, 30 Aug 2021 14:46:43 -0400
| Newsgroups | gmane.comp.java.roller.user |
|---|---|
| Message-ID | <CAAw2B3gtJWFgwQW=cSJDuQ-eK91Af7220Q4Nynr_T66BWaW7YQ@mail.gmail.com> |
--000000000000cb575905cacb410a
Content-Type: multipart/alternative; boundary="000000000000cb575705cacb4109"
--000000000000cb575705cacb4109
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Apache roller community/Security team,
We are on Apache Roller 6.0.1 and our recent pen test shows
this below xss vulnerability. https://www.cvedetails.com/cve/CVE-2019-0234=
/
recommends to upgrade Roller blog to 5.2.3, but even with 6.0.1 issue
persists.
Hope we will have security patch for this soon.
Thanks
Naren
*FINDING 3.1 *
*Title *
Reflected Cross Site Scripting (XSS)
*Impact *
An attacker could use this vulnerability to execute arbitrary JavaScript
within the victim=E2=80=99s browser. This could allow an attacker to hijack
sessions, access data that the victim can access, or force the browser to
perform unwanted actions such as redirecting to malware or a phishing page.
*Recommendations *
Sanitize all user controlled input that is submitted to the application and
filter for JavaScript injection statements. Input that contains potentially
dangerous characters should not be processed by the application. Escape any
user controlled input that is incorporated in the application response.
*Additional Information *
*NIST SP 800-53 Reference *
SI-10 Information Input Validation
*Testing Process and Evidence *
The pentest team discovered that a captcha in the form of a math equation
solution is required when submitting comments on blog posts. The solution
to the math problem is submitted as the value of the answer parameter in a
request to the /blog/director/entry/testing-after-pvt-migration-to URL and
the value is incoporated unsanitized in the application response. The
screenshot below demonstrates submitting a cross site scripting payload as
the value of the answer parameter.
*XSS payload submitted as the value of the answer parameter*
The application reflects the value submitted in the =E2=80=9Canswer=E2=80=
=9D parameter as
part of a message that the math
equation was not solved correctly. This results in the execution of
submitted cross site scripting payload.
The screenshot below demonstrates the execution of JavaScript alert() with
the value of document.domain
#############################
This was reported in 2019
On 2019/07/11 22:14:27, Dave <[email protected]> wrote:
> Severity: Important>
>
> Vendor: The Apache Software Foundation>
>
> Versions affected: Roller 5.2, 5.2.1, 5.2.2. The unsupported pre-Roller
5.1>
> versions may also be affected.>
>
> Description: Roller's Math Comment Authenticator did not property
sanitize>
> user input and could be exploited to perform Reflected Cross Site
Scripting>
> (XSS).>
>
> Mitigation: The mitigation for this vulnerability is to upgrade to the>
> lastest version of Roller, which is now Roller 5.2.3.>
>
> Credit: This issue was discovered and reported by Muthukumar Marikani>
>
--=20
Naren
--000000000000cb575705cacb4109
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div><br></div><div><div class=3D"gmail_quote" dir=3D"auto"><div lang=3D"EN=
-US" link=3D"#0563C1" vlink=3D"#954F72"><div class=3D"m_-450738927672561109=
6WordSection1"><p class=3D"MsoNormal"><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">Apache roller community/Sec=
urity team,<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 We are on Apache Roller 6.0.1=C2=A0=
and our recent pen test shows this below xss vulnerability.=C2=A0
<a href=3D"https://www.cvedetails.com/cve/CVE-2019-0234/" target=3D"_blank"=
>https://www.cvedetails.com/cve/CVE-2019-0234/</a> recommends to upgrade Ro=
ller blog to 5.2.3, but even with 6.0.1 issue persists.<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">Hope we will have=C2=A0 sec=
urity patch for this soon.<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">Thanks<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">Naren<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" style=3D"border-col=
lapse:collapse">
<tbody>
<tr style=3D"height:7.4pt">
<td colspan=3D"2" valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;heigh=
t:7.4pt">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:10.0=
pt;color:white">FINDING 3.1 </span>
</b><span style=3D"font-size:10.0pt"><u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:.15in">
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:.15in">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:11.0=
pt;font-family:"Times New Roman",serif">Title
</span></b><span style=3D"font-size:11.0pt"><u></u><u></u></span></p>
</td>
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:.15in">
<p class=3D"m_-4507389276725611096Default"><span style=3D"font-size:11.0pt;=
font-family:"Times New Roman",serif">Reflected Cross Site Scripti=
ng (XSS)
<u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:26.4pt">
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:26.4pt">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:11.0=
pt;font-family:"Times New Roman",serif">Impact
</span></b><span style=3D"font-size:11.0pt"><u></u><u></u></span></p>
</td>
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:26.4pt">
<p class=3D"m_-4507389276725611096Default"><span style=3D"font-size:11.0pt;=
font-family:"Times New Roman",serif">An attacker could use this v=
ulnerability to execute arbitrary JavaScript within the victim=E2=80=99s br=
owser. This could allow an attacker to hijack sessions, access data that th=
e
victim can access, or force the browser to perform unwanted actions such a=
s redirecting to malware or a phishing page.
<u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:26.4pt">
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:26.4pt">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:11.0=
pt;font-family:"Times New Roman",serif">Recommendations
</span></b><span style=3D"font-size:11.0pt"><u></u><u></u></span></p>
</td>
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:26.4pt">
<p class=3D"m_-4507389276725611096Default"><span style=3D"font-size:11.0pt;=
font-family:"Times New Roman",serif">Sanitize all user controlled=
input that is submitted to the application and filter for JavaScript injec=
tion statements. Input that contains potentially dangerous characters
should not be processed by the application. Escape any user controlled inp=
ut that is incorporated in the application response.
<u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:10.4pt">
<td colspan=3D"2" valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;heigh=
t:10.4pt">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:11.0=
pt;font-family:"Times New Roman",serif">Additional Information
</span></b><span style=3D"font-size:11.0pt"><u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:16.4pt">
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:16.4pt">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:11.0=
pt;font-family:"Times New Roman",serif">NIST SP 800-53 Reference
</span></b><span style=3D"font-size:11.0pt;font-family:"Times New Roma=
n",serif"><u></u><u></u></span></p>
</td>
<td valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;height:16.4pt">
<p class=3D"m_-4507389276725611096Default"><span style=3D"font-size:11.0pt;=
font-family:"Times New Roman",serif">SI-10 Information Input Vali=
dation
<u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:10.4pt">
<td colspan=3D"2" valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;heigh=
t:10.4pt">
<p class=3D"m_-4507389276725611096Default"><b><span style=3D"font-size:11.0=
pt;font-family:"Times New Roman",serif">Testing Process and Evide=
nce
</span></b><span style=3D"font-size:11.0pt"><u></u><u></u></span></p>
</td>
</tr>
<tr style=3D"height:32.7pt">
<td colspan=3D"2" valign=3D"top" style=3D"padding:0in 5.4pt 0in 5.4pt;heigh=
t:32.7pt">
<p class=3D"m_-4507389276725611096Default"><span style=3D"font-size:11.0pt;=
font-family:"Times New Roman",serif">The pentest team discovered =
that a captcha in the form of a math equation solution is required when sub=
mitting comments on blog posts. The solution to the math problem is
submitted as the value of the answer parameter in a request to the /blog/d=
irector/entry/testing-after-pvt-migration-to URL and the value is incoporat=
ed unsanitized in the application response. The screenshot below demonstrat=
es submitting a cross site scripting
payload as the value of the answer parameter. <u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
<p class=3D"m_-4507389276725611096MsoPlainText"><img border=3D"0" src=3D"ci=
d:17b9860c6e14cd34f0f1" style=3D"width:731px;max-width:100%"><u></u><u></u>=
</p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><b>XSS payload submitted as=
the value of the answer parameter<u></u><u></u></b></p>
<p class=3D"m_-4507389276725611096MsoPlainText">The application reflects th=
e value submitted in the =E2=80=9Canswer=E2=80=9D parameter as part of a me=
ssage that the math
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">equation was not solved cor=
rectly. This results in the execution of submitted cross site scripting pay=
load.
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">The screenshot below demons=
trates the execution of JavaScript alert() with the value of document.domai=
n<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><img border=3D"0" src=3D"ci=
d:17b9860c6e1155f77112" style=3D"width:313px;max-width:100%"><u></u><u></u>=
</p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText"><u></u>=C2=A0<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText" dir=3D"auto"><u></u>=C2=A0#=
############################<u></u></p><p class=3D"m_-4507389276725611096Ms=
oPlainText" dir=3D"auto">This was reported in 2019</p>
<p class=3D"m_-4507389276725611096MsoPlainText">On 2019/07/11 22:14:27, Dav=
e <<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a=
>> wrote:
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> Severity: Important>=
; <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> Vendor: The Apache Sof=
tware Foundation> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> Versions affected: Rol=
ler 5.2, 5.2.1, 5.2.2. The unsupported pre-Roller 5.1>
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> versions may also be a=
ffected.> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> Description: Roller=
9;s Math Comment Authenticator did not property sanitize>
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> user input and could b=
e exploited to perform Reflected Cross Site Scripting>
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> (XSS).> <u></u><u><=
/u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> Mitigation: The mitiga=
tion for this vulnerability is to upgrade to the>
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> lastest version of Rol=
ler, which is now Roller 5.2.3.> <u></u>
<u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> <u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> Credit: This issue was=
discovered and reported by Muthukumar Marikani>
<u></u><u></u></p>
<p class=3D"m_-4507389276725611096MsoPlainText">> <u></u><u></u></p>
</div>
</div>
</div></div>-- <br><div dir=3D"ltr" class=3D"gmail_signature" data-smartmai=
l=3D"gmail_signature"><div dir=3D"ltr"><div>Naren<br><br></div></div></div>
--000000000000cb575705cacb4109--
--000000000000cb575905cacb410a--