Jive Software Open Source

  • Log In Access more options
    • Online Help
    • Keyboard Shortcuts
    • About JIRA
    • JIRA Credits
    • What’s New
  • Dashboards Access more options (Alt+d)
  • Projects Access more options (Alt+p)
  • Issues Access more options (Alt+i)
  • Openfire (ARCHIVED)
  • JM-629

Additional cross-site scripting bugs in login

  • Log In
  • Views
    • XML
    • Word
    • Printable

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Blocker Blocker
  • Resolution: Fixed
  • Affects Version/s: 2.6.0
  • Fix Version/s: 3.6.0
  • Component/s: Admin Console
  • Labels:
    None
  • Acceptance Test - Add?:
    No

Description

Additional cross-site scripting attacks possible in the login form.

Issue Links

is related to

Bug - A problem which impairs or prevents the functions of the product. OF-90 Cross-site scripting attack in the login form

  • Blocker - Blocks development and/or testing work, production could not run.
  • Resolved - A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.

Bug - A problem which impairs or prevents the functions of the product. JM-1489 Authentication bypass allowing arbitrary code execution

  • Blocker - Blocks development and/or testing work, production could not run.
  • Closed - The issue is considered finished, the resolution is correct. Issues which are not closed can be reopened.

Bug - A problem which impairs or prevents the functions of the product. JM-1488 CallLogDAO in SIP Plugin enables SQL Injection

  • Major - Major loss of function.
  • Closed - The issue is considered finished, the resolution is correct. Issues which are not closed can be reopened.

Activity

Ascending order - Click to sort in descending order
  • All
  • Comments
  • Work Log
  • History
  • Activity
  • Source
  • Reviews
  • Builds
Hide
Permalink
LG added a comment - 05/21/08 09:45 PM

Hi,

I really wonder why it take so long to resolve this issue. Just ignoring the parsed parameters (everything behind the ?) would be fine to fix this issue.
Of course one would no longer be able to access URL's directly and to set the username but that's how other applications solve this issue.

LG

Show
LG added a comment - 05/21/08 09:45 PM Hi, I really wonder why it take so long to resolve this issue. Just ignoring the parsed parameters (everything behind the ?) would be fine to fix this issue. Of course one would no longer be able to access URL's directly and to set the username but that's how other applications solve this issue. LG
Hide
Permalink
Daniel Henninger added a comment - 05/22/08 03:21 AM

Patience =) I aim to fix these and some other assorted issues for 3.5.2!

Show
Daniel Henninger added a comment - 05/22/08 03:21 AM Patience =) I aim to fix these and some other assorted issues for 3.5.2!
Hide
Permalink
Daniel Henninger added a comment - 07/17/08 05:00 PM

A trivial demo of this:
http://blathersource.org:9090/login.jsp?url=%22%3E%3Cscript%20type=%22text/javascript%22%3Ealert(%22hi%22)%3C/script%3E

Show
Daniel Henninger added a comment - 07/17/08 05:00 PM A trivial demo of this: http://blathersource.org:9090/login.jsp?url=%22%3E%3Cscript%20type=%22text/javascript%22%3Ealert(%22hi%22)%3C/script%3E

People

  • Assignee:
    Daniel Henninger
    Reporter:
    Matt Tucker
Vote (7)
Watch (3)

Dates

  • Created:
    04/07/06 08:38 PM
    Updated:
    11/12/08 09:41 AM
    Resolved:
    08/25/08 06:48 PM
  • Atlassian JIRA (v5.0.4#731-sha1:3aa7374)
  • Report a problem
  • Powered by a free Atlassian JIRA open source license for igniterealtime.org. Try JIRA - bug tracking software for your team.