[Bug 1166041] CVE-2010-5312 jquery-ui: XSS vulnerability in jQuery.ui.dialog title option

bugzilla at redhat.com bugzilla at redhat.com
Tue Mar 3 16:22:58 UTC 2015


https://bugzilla.redhat.com/show_bug.cgi?id=1166041

Ján Rusnačko <jrusnack at redhat.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |jrusnack at redhat.com
         Whiteboard|impact=moderate,public=2010 |impact=moderate,public=2010
                   |0903,reported=20141120,sour |0903,reported=20141120,sour
                   |ce=internet,cvss2=4.3/AV:N/ |ce=internet,cvss2=4.3/AV:N/
                   |AC:M/Au:N/C:N/I:P/A:N,fedor |AC:M/Au:N/C:N/I:P/A:N,fedor
                   |a-all/asterisk-gui=affected |a-all/asterisk-gui=affected
                   |,fedora-all/beacon=affected |,fedora-all/beacon=affected
                   |,fedora-all/blender=affecte |,fedora-all/blender=affecte
                   |d,fedora-all/bodhi=affected |d,fedora-all/bodhi=affected
                   |,fedora-all/cacti=affected, |,fedora-all/cacti=affected,
                   |fedora-all/calibre=affected |fedora-all/calibre=affected
                   |,fedora-all/cinnamon=notaff |,fedora-all/cinnamon=notaff
                   |ected,fedora-all/ckeditor=a |ected,fedora-all/ckeditor=a
                   |ffected,fedora-all/cobbler= |ffected,fedora-all/cobbler=
                   |affected,fedora-all/couchdb |affected,fedora-all/couchdb
                   |=affected,fedora-all/cumin= |=affected,fedora-all/cumin=
                   |affected,fedora-all/django- |affected,fedora-all/django-
                   |typepad=affected,fedora-all |typepad=affected,fedora-all
                   |/dl=notaffected,fedora-all/ |/dl=notaffected,fedora-all/
                   |dokuwiki=affected,fedora-al |dokuwiki=affected,fedora-al
                   |l/drupal6=affected,fedora-a |l/drupal6=affected,fedora-a
                   |ll/drupal7=affected,fedora- |ll/drupal7=affected,fedora-
                   |all/drupal7-jquery_update=a |all/drupal7-jquery_update=a
                   |ffected,fedora-all/fish=aff |ffected,fedora-all/fish=aff
                   |ected,fedora-all/fityk=nota |ected,fedora-all/fityk=nota
                   |ffected,fedora-all/freeipa= |ffected,fedora-all/freeipa=
                   |affected,fedora-all/gallery |affected,fedora-all/gallery
                   |3=affected,fedora-all/globa |3=affected,fedora-all/globa
                   |l=affected,fedora-all/graph |l=affected,fedora-all/graph
                   |ite-web=affected,fedora-all |ite-web=affected,fedora-all
                   |/hotot=affected,fedora-all/ |/hotot=affected,fedora-all/
                   |ikiwiki=affected,fedora-all |ikiwiki=affected,fedora-all
                   |/libgda=affected,fedora-all |/libgda=affected,fedora-all
                   |/mediawiki=affected,fedora- |/mediawiki=affected,fedora-
                   |all/mojomojo=affected,fedor |all/mojomojo=affected,fedor
                   |a-all/nodejs-should=affecte |a-all/nodejs-should=affecte
                   |d,fedora-all/OpenLP=notaffe |d,fedora-all/OpenLP=notaffe
                   |cted,fedora-all/openslides= |cted,fedora-all/openslides=
                   |affected,fedora-all/opentea |affected,fedora-all/opentea
                   |cher=affected,fedora-all/or |cher=affected,fedora-all/or
                   |bited=affected,fedora-all/p |bited=affected,fedora-all/p
                   |erl-Mojolicious=affected,fe |erl-Mojolicious=affected,fe
                   |dora-all/phpPgAdmin=affecte |dora-all/phpPgAdmin=affecte
                   |d,fedora-all/python-backlas |d,fedora-all/python-backlas
                   |h=affected,fedora-all/pytho |h=affected,fedora-all/pytho
                   |n-django=affected,fedora-al |n-django=affected,fedora-al
                   |l/python-django-debug-toolb |l/python-django-debug-toolb
                   |ar=affected,fedora-all/pyth |ar=affected,fedora-all/pyth
                   |on-django-typepadapp=affect |on-django-typepadapp=affect
                   |ed,fedora-all/python-django |ed,fedora-all/python-django
                   |14=affected,fedora-all/pyth |14=affected,fedora-all/pyth
                   |on-django15=affected,fedora |on-django15=affected,fedora
                   |-all/python-flask-debugtool |-all/python-flask-debugtool
                   |bar=affected,fedora-all/pyt |bar=affected,fedora-all/pyt
                   |hon-pebl=affected,fedora-al |hon-pebl=affected,fedora-al
                   |l/python-sphinx=affected,fe |l/python-sphinx=affected,fe
                   |dora-all/python-tw-jquery=a |dora-all/python-tw-jquery=a
                   |ffected,fedora-all/python-t |ffected,fedora-all/python-t
                   |w2-jqplugins-flot=affected, |w2-jqplugins-flot=affected,
                   |fedora-all/python-tw2-jquer |fedora-all/python-tw2-jquer
                   |y=affected,fedora-all/pytho |y=affected,fedora-all/pytho
                   |n-werkzeug=affected,fedora- |n-werkzeug=affected,fedora-
                   |all/python-XStatic-jQuery=a |all/python-XStatic-jQuery=a
                   |ffected,fedora-all/python-b |ffected,fedora-all/python-w
                   |acklash=affected,fedora-all |erkzeug=affected,fedora-all
                   |/python-django=affected,fed |/roundup=affected,fedora-al
                   |ora-all/python-sphinx=affec |l/rubygem-jquery-rails=affe
                   |ted,fedora-all/python-werkz |cted,fedora-all/sagemath=af
                   |eug=affected,fedora-all/rou |fected,fedora-all/sparklesh
                   |ndup=affected,fedora-all/ru |are=affected,fedora-all/spy
                   |bygem-jquery-rails=affected |der=affected,fedora-all/Sta
                   |,fedora-all/sagemath=affect |rCluster=affected,fedora-al
                   |ed,fedora-all/sparkleshare= |l/sticky-notes=notaffected,
                   |affected,fedora-all/spyder= |fedora-all/sugar-help=affec
                   |affected,fedora-all/StarClu |ted,fedora-all/varnish-agen
                   |ster=affected,fedora-all/st |t=affected,fedora-all/webac
                   |icky-notes=notaffected,fedo |ula=affected,fedora-all/wes
                   |ra-all/sugar-help=affected, |noth=affected,fedora-all/wh
                   |fedora-all/varnish-agent=af |y3=affected,fedora-all/word
                   |fected,fedora-all/webacula= |press=affected,fedora-all/y
                   |affected,fedora-all/wesnoth |elp-xsl=affected,fedora-all
                   |=affected,fedora-all/why3=a |/zabbix=affected,epel-all/d
                   |ffected,fedora-all/wordpres |rupal7-jquery_update=affect
                   |s=affected,fedora-all/yelp- |ed,epel-all/python-tw-jquer
                   |xsl=affected,fedora-all/zab |y=affected,epel-all/python-
                   |bix=affected,epel-all/drupa |tw2-jquery=affected,epel-al
                   |l7-jquery_update=affected,e |l/python-XStatic-jquery-ui=
                   |pel-all/python-tw-jquery=af |affected,openshift-1/drupal
                   |fected,epel-all/python-tw2- |6-jquery_ui-lib=new,openshi
                   |jquery=affected,epel-all/py |ft-1/ruby193-rubygem-jquery
                   |thon-XStatic-jquery-ui=affe |-rails=new,openshift-enterp
                   |cted,openshift-1/drupal6-jq |rise-1/ruby193-rubygem-jque
                   |uery_ui-lib=new,openshift-1 |ry-rails=new,openshift-ente
                   |/ruby193-rubygem-jquery-rai |rprise-2/ruby193-rubygem-jq
                   |ls=new,openshift-enterprise |uery-rails=new,rhscl-1.2/ro
                   |-1/ruby193-rubygem-jquery-r |r40-rubygem-jquery-rails=ne
                   |ails=new,openshift-enterpri |w,rhscl-1.2/ruby193-rubygem
                   |se-2/ruby193-rubygem-jquery |-jquery-rails=new,rhn_satel
                   |-rails=new,rhscl-1.2/ror40- |lite_6/ruby193-rubygem-jque
                   |rubygem-jquery-rails=new,rh |ry-ui-rails=new,sam-1/ruby1
                   |scl-1.2/ruby193-rubygem-jqu |93-rubygem-jquery-rails=new
                   |ery-rails=new,rhn_satellite |,cfme-5/ruby193-rubygem-jqu
                   |_6/ruby193-rubygem-jquery-u |ery-rails=new,openstack-4/r
                   |i-rails=new,sam-1/ruby193-r |uby193-rubygem-jquery-rails
                   |ubygem-jquery-rails=new,cfm |=new,openstack-foreman/ruby
                   |e-5/ruby193-rubygem-jquery- |193-rubygem-jquery-ui-rails
                   |rails=new,openstack-4/ruby1 |=new,rhel-6/ipa=affected,rh
                   |93-rubygem-jquery-rails=new |el-6/python-sphinx=new,rhel
                   |,openstack-foreman/ruby193- |-7/ipa=affected,rhel-7/pyth
                   |rubygem-jquery-ui-rails=new |on-sphinx=new,rhel-7/yelp-x
                   |,rhel-6/ipa=affected,rhel-6 |sl=new
                   |/python-sphinx=new,rhel-7/i |
                   |pa=affected,rhel-7/python-s |
                   |phinx=new,rhel-7/yelp-xsl=n |
                   |ew                          |



--- Comment #68 from Ján Rusnačko <jrusnack at redhat.com> ---
Deleting duplicate fedora-all/python-werkzeug=, fedora-all/python-sphinx=,
fedora-all/python-django= from whiteboard.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=lLbJF6Zftl&a=cc_unsubscribe


More information about the perl-devel mailing list