|
Message-ID: <CALLT8khyoJnN0vcmNna9Ah6mODNdfeYiMFuNNfNHs7t_=Zuuwg@mail.gmail.com> Date: Thu, 18 May 2017 19:27:58 -0400 From: "Alex O'Ree" <alexoree@...che.org> To: oss-security@...ts.openwall.com, "user@...di.apache.org" <user@...di.apache.org>, dev@...di.apache.org, bugtraq@...urityfocus.com, awillard@...egroundsecurity.com, pavelp@...hat.com Subject: jUDDI Security Bulletin [CVEID]:CVE-2015-5241 [PRODUCT]:Apache jUDDI [VERSION]: 3.1.2, 3.1.3, 3.1.4, and 3.1.5 utilize the portlets based user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or 'uddi-console' [PROBLEMTYPE]:Open Redirect [REFERENCES]:http://juddi.apache.org/security.html [DESCRIPTION]: After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious user to redirect the browser to an unintended web page. User session data, credentials, and auth tokens are cleared before the redirect. Mitigation: 1) Remove or disable the portlet's based user interface. 2) Upgrade to newer versions of jUDDI (v3.2 and newer) which is not affected by this issue 3) If upgrading or disabling the portlet based user interface is not an option, the following can be used to resolve the issue. Modify the file located at "uddi-portlets/logout.jsp", replacing the following text > "String redirectURL = (String) request.getParameter("urlredirect"); > if (redirectURL==null) redirectURL = "/pluto/Logout"; with this text > String redirectURL = "/pluto/Logout"; No patches or releases are planned for the affected versions since jUDDI v3.2 replaced the user interface.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.