Bug 27757 - ganglia-web new security issues CVE-2019-2037[89]
Summary: ganglia-web new security issues CVE-2019-2037[89]
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Johnny A. Solbu
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-12-06 03:06 CET by Zombie Ryushu
Modified: 2024-03-13 13:54 CET (History)
2 users (show)

See Also:
Source RPM: ganglia-web-3.7.4-4.mga8.src.rpm
CVE: CVE-2019-20379
Status comment:


Attachments

Description Zombie Ryushu 2020-12-06 03:06:47 CET
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
Zombie Ryushu 2020-12-06 03:06:58 CET

CVE: (none) => CVE-2019-20379
Component: RPM Packages => Security
QA Contact: (none) => security

Comment 1 David Walser 2020-12-06 03:23:18 CET
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20379

Source RPM: ganglia-web-3.7.4-4.mga8.src => ganglia-web-3.7.4-4.mga8.src.rpm
Whiteboard: (none) => MGA7TOO

Comment 2 Aurelien Oudelet 2020-12-07 10:24:32 CET
Hi, thanks for reporting this bug.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

CC: (none) => ouaurelien
Assignee: bugsquad => cooker

David Walser 2020-12-27 22:33:12 CET

Status comment: (none) => No fix available as of end of 2020

David Walser 2020-12-28 17:10:21 CET

Whiteboard: MGA7TOO => MGA8TOO, MGA7TOO

Comment 3 Johnny A. Solbu 2021-05-13 02:11:55 CEST
Link to upstream bug repport

See Also: (none) => https://github.com/ganglia/ganglia-web/issues/351

Comment 4 David Walser 2021-07-01 18:46:40 CEST
Removing Mageia 7 from whiteboard due to EOL:
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Whiteboard: MGA8TOO, MGA7TOO => MGA8TOO

Comment 5 David Walser 2022-11-09 17:43:40 CET
SUSE has issued an advisory on November 8:
https://lists.suse.com/pipermail/sle-security-updates/2022-November/012840.html

CVE-2019-20378 appears to be related and to have been fixed last year (and in 3.7.5), and CVE-2019-20379 (or I may have the CVEs backwards) appears to require an additional patch.

Status comment: No fix available as of end of 2020 => Fixed upstream in 3.7.5 and/or in patch available from SUSE
Summary: ganglia-web security vulnerability CVE-2019-20379 => ganglia-web new security issues CVE-2019-2037[89]

Comment 6 Johnny A. Solbu 2022-11-09 22:58:43 CET
(In reply to David Walser from comment #5)
> SUSE has issued an advisory on November 8:
> https://lists.suse.com/pipermail/sle-security-updates/2022-November/012840.
> html
> 
> CVE-2019-20378 appears to be related and to have been fixed last year (and
> in 3.7.5), and CVE-2019-20379 (or I may have the CVEs backwards) appears to
> require an additional patch.

v3.7.5 submitted to cauldron.

Do you have a link to any patches?
My searches finds that upstream can't reproduce the issue…
Comment 7 David Walser 2022-11-10 00:55:34 CET
I don't see any patches on top of 3.7.5 added in openSUSE Factory.

See if any of the fixes referenced here are missing from 3.7.5:
https://bugzilla.suse.com/show_bug.cgi?id=1160761
Comment 8 Johnny A. Solbu 2022-11-10 01:04:08 CET
(In reply to David Walser from comment #7)
> I don't see any patches on top of 3.7.5 added in openSUSE Factory.
> 
> See if any of the fixes referenced here are missing from 3.7.5:
> https://bugzilla.suse.com/show_bug.cgi?id=1160761

I just viewed the spec diff SuSE claim fixes the issue, which is this one:
https://build.opensuse.org/request/show/1032451

This is BULLSHIT!
There is no patch changes of any kind!
Comment 9 David Walser 2022-11-10 02:19:01 CET
No, the update to 3.7.5 was actually the commit before that one, but it was just a simple update to 3.7.5.  I'm guessing that the patches are upstream in 3.7.5, but I haven't checked to verify that.
Comment 10 Nicolas Salguero 2024-03-13 13:54:16 CET
Mageia 8 EOL.

Version: Cauldron => 8
Status: NEW => RESOLVED
Status comment: Fixed upstream in 3.7.5 and/or in patch available from SUSE => (none)
Whiteboard: MGA8TOO => (none)
Resolution: (none) => OLD
CC: (none) => nicolas.salguero


Note You need to log in before you can comment on or make changes to this bug.