Jetspeed 2
  1. Jetspeed 2
  2. JS2-1075

possible cross site scripting during login

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.1.4, 2.2.1
    • Component/s: Security
    • Labels:
      None
    • Environment:
      all env

      Description

      user can specify during login script, which isn't html escaped in WEB-INF/templates/login/html/login.jsp page

      solution, escapeHtml input strings, like this:

      <%
      String ln = "";
      String pa = "";

      Object ln_o = session.getAttribute(LoginConstants.USERNAME);
      Object pa_o = session.getAttribute(LoginConstants.PASSWORD);

      if (ln_o != null) ln = (String)ln_o;
      if (pa_o != null) pa = (String)pa_o;

      %>
      <input type='hidden' name='j_username' value='<%= StringEscapeUtils.escapeHtml(ln) %>'/>
      <input type='hidden' name='j_password' value='<%= StringEscapeUtils.escapeHtml(pa) %>'/>

        Activity

        Hide
        Ate Douma added a comment -

        Fixed by escaping input values within LoginProxyServlet.
        Thanks for the report Radko!

        Show
        Ate Douma added a comment - Fixed by escaping input values within LoginProxyServlet. Thanks for the report Radko!

          People

          • Assignee:
            Ate Douma
            Reporter:
            radko keves
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development