2 Oct 2010 02:48
[SECURITY ALERT] XSS Vulnerability in Console - 0.8.0p1 and 0.8.1p1
SUMMARY Amber Yust has discovered and fixed several cross-site scripting vulnerabilities in the Buildbot console. This vulnerability allows an attacker to craft a URL targetting a specific Buildbot instance, and run arbitrary browser-side code in the context of that Buildbot instance. This constitutes a security risk both for the Buildbot instance and for any other services hosted on the same domain as that Buildbot instance, and is a particular threat when browsers' same-origin policy is used to protect sensitive information such as cookies. Note that Buildbot itself does not use cookies (even in the IAuth framework), so the risk for a standalone buildbot instance is somewhat limited. Even so, all users are urged to upgrade or apply the patch given in the MITIGATION section, below. The vulnerabilities are limited to the console view, and do not affect Buildbot slaves. AFFECTED VERSIONS buildbot-0.8.0 buildbot-0.8.1 UNAFFECTED VERSIONS all earlier versions MITIGATION All users of Buildbot are urged to patch their installations. Patches(Continue reading)
RSS Feed