CVE-2011-4312
published 2011-11-24CVE-2011-4312: Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.25%
81.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| reviewboard | review_board | <= 1.5.6 | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
| reviewboard | review_board | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4312 ReviewBoard: XSS in the commenting system (diff viewer and screenshot pages) [fedora-all]
bugzilla·2011-11-15·CVSS 4.3
CVE-2011-4312 [MEDIUM] CVE-2011-4312 ReviewBoard: XSS in the commenting system (diff viewer and screenshot pages) [fedora-all]
CVE-2011-4312 ReviewBoard: XSS in the commenting system (diff viewer and screenshot pages) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org
Bugzilla
CVE-2011-4312 ReviewBoard: XSS in the commenting system (diff viewer and screenshot pages)
bugzilla·2011-11-15·CVSS 4.3
CVE-2011-4312 [MEDIUM] CVE-2011-4312 ReviewBoard: XSS in the commenting system (diff viewer and screenshot pages)
CVE-2011-4312 ReviewBoard: XSS in the commenting system (diff viewer and screenshot pages)
A cross-site scripting (XSS) flaw was found in the way the commenting system of the ReviewBoard, a web-based code review tool, sanitized user input (new comments to be loaded). A remote attacker could provide a specially-crafted URL, which once visited by valid ReviewBoard user could lead to arbitrary HTML or web script execution in the 'diff viewer' or 'screenshot pages' components.
References:
[1] http://www.reviewboard.org/news/
[2] http://www.reviewboard.org/docs/releasenotes/dev/reviewboard/1.6.3/
Relevant upstream patch:
[3] https://github.com/reviewboard/reviewboard/commit/7a0a9d94555502278534dedcf2d75e9fccce8c3d
Discussion:
This issue has been scheduled to be corrected by the following R
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/070091.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/070176.htmlhttp://secunia.com/advisories/46840http://www.openwall.com/lists/oss-security/2011/11/15/8http://www.openwall.com/lists/oss-security/2011/11/15/9http://www.reviewboard.org/docs/releasenotes/dev/reviewboard/1.6.3/http://www.securityfocus.com/bid/50681https://bugzilla.redhat.com/show_bug.cgi?id=754126https://github.com/reviewboard/reviewboard/commit/7a0a9d94555502278534dedcf2d75e9fccce8c3dhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/070091.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/070176.htmlhttp://secunia.com/advisories/46840http://www.openwall.com/lists/oss-security/2011/11/15/8http://www.openwall.com/lists/oss-security/2011/11/15/9http://www.reviewboard.org/docs/releasenotes/dev/reviewboard/1.6.3/http://www.securityfocus.com/bid/50681https://bugzilla.redhat.com/show_bug.cgi?id=754126https://github.com/reviewboard/reviewboard/commit/7a0a9d94555502278534dedcf2d75e9fccce8c3d
2011-11-24
Published