Bug 47998 - univention-web / dojox: Security vulnerabiliy (4.2)
univention-web / dojox: Security vulnerabiliy (4.2)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: UMC (Generic)
UCS 4.2
All Linux
: P2 normal (vote)
: UCS 4.2-5-errata
Assigned To: Ole Schwiegert
Johannes Keiser
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-10-16 08:57 CEST by Philipp Hahn
Modified: 2018-11-28 12:29 CET (History)
3 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Philipp Hahn univentionstaff 2018-10-16 08:57:47 CEST
All versions of univention-web since UCS-4.2 contain a vulnerable version of DojoX:

CVE-2018-15494: In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid

Debian fixed it for Jessie with <https://lists.debian.org/debian-lts-announce/2018/09/msg00002.html>, which is included in UCS-4.2-5, but univention-web contains its own unfixed version!

+++ This bug was initially created as a clone of Bug #47997 +++
Comment 1 Ole Schwiegert univentionstaff 2018-11-07 11:36:53 CET
Package: univention-dojo
Version: 10.0.1-1A~4.2.0.201811071125
Branch: ucs_4.2-0
Scope: errata4.2-5

Package: univention-web
Version: 1.0.42-68A~4.2.0.201811071131
Branch: ucs_4.2-0
Scope: errata4.2-5

Bumped dojo version to 1.12.4
Added ca-certificates to build-deps of univention-dojo
Comment 2 Johannes Keiser univentionstaff 2018-11-22 09:58:53 CET
OK: security fix was backported to dojo 1.12.4. Version updated to 1.12.4. Fixes are present
OK: No major changes since 1.12.1
OK: YAML
-> verified