oss-sec mailing list archives

[CVE-2015-5215] Ipsilon: XSS in multiple pages


From: Patrick Uiterwijk <puiterwijk () redhat com>
Date: Fri, 23 Oct 2015 15:19:11 +0200

CVE-2015-5215: Ipsilon XSS in multiple pages

Versions affected: 0.1.0 to 1.0.0
Fixed in versions: 1.0.1, 1.1.0

Description:
It was found that the Ipsilon IdP server used the default configuration of the Jinja templating engine, which did not 
HTML escape template variables. This could be exploited to perform an XSS attack if a value from untrusted input was 
used in the template and rendered in the user`s browser.

Mitigation:
Users of Ipsilon should update to version 1.0.1 or later.

Credit:
This issue was discovered by Michael Scherer of Red Hat.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1255168


-- 
Patrick Uiterwijk
Fedora Infrastructure Team


Current thread: