Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CALLT8khyoJnN0vcmNna9Ah6mODNdfeYiMFuNNfNHs7t_=Zuuwg@mail.gmail.com>
Date: Thu, 18 May 2017 19:27:58 -0400
From: "Alex O'Ree" <alexoree@...che.org>
To: oss-security@...ts.openwall.com, 
	"user@...di.apache.org" <user@...di.apache.org>, dev@...di.apache.org, bugtraq@...urityfocus.com, 
	awillard@...egroundsecurity.com, pavelp@...hat.com
Subject: jUDDI Security Bulletin

[CVEID]:CVE-2015-5241
[PRODUCT]:Apache jUDDI
[VERSION]: 3.1.2, 3.1.3, 3.1.4, and 3.1.5 utilize the portlets based
user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or
'uddi-console'

[PROBLEMTYPE]:Open Redirect
[REFERENCES]:http://juddi.apache.org/security.html

[DESCRIPTION]: After logging into the portal, the logout jsp page
redirects the browser back to the login page after. It is feasible for
malicious user to redirect the browser to an unintended web page. User
session data, credentials, and auth tokens are cleared before the
redirect.


Mitigation:

1) Remove or disable the portlet's based user interface.

2) Upgrade to newer versions of jUDDI (v3.2 and newer) which is not
affected by this issue

3) If upgrading or disabling the portlet based user interface is not
an option, the following can be used to resolve the issue. Modify the
file located at "uddi-portlets/logout.jsp", replacing the following
text

> "String redirectURL = (String) request.getParameter("urlredirect");
> if (redirectURL==null) redirectURL = "/pluto/Logout";

with this text
> String redirectURL = "/pluto/Logout";

No patches or releases are planned for the affected versions since
jUDDI v3.2 replaced the user interface.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.