Описание
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
Отчет
This Moderate impact Cross-Site Scripting (XSS) flaw in Jastow, as used in Red Hat Enterprise Application Platform, arises when a server is configured to allow unescaped characters in URLs with embedded Undertow. Exploitation requires a specific, non-default configuration, limiting its applicability in typical deployments.
Меры по смягчению последствий
It is possible to contruct successful attack vector if and only if customer or client is using embedded Undertow and Jastow together in their application and the following conditions are met:
- Undertow was configured with UndertowOptions.ALLOW_UNESCAPED_CHARACTERS_IN_URL set to 'true' value
- DeploymentInfo configured with setEscapeErrorMessage(true) method was passed to Undertow's Servlet Container instance
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | io.undertow.jastow-jastow | Affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | jastow | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | jastow | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | io.undertow.jastow-jastow | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jastow | Fix deferred |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
6.5 Medium
CVSS3