(Created page with "{{Featurepage|featured=true|featuredesc=Current Security Advisory: BSSA-2023-01|featurestart=07/26/2023}} {| class="wikitable" |+ ! ! |- |Date |2023-07-25 |- |Severity |Medium |- |Affected | * BlueSpice Infrastructure: Ghostscript |- |Fixed in | * Ghostscript 9.53.3 and 10.01.2 |- |CVE |[https://www.cve.org/CVERecord?id=CVE-2023-36664 CVE-2023-36664] |} == Problem == A bug in ghostscript can be exploited to run arbitrary code on the host machine using prepared PDF docum...") |
No edit summary Tag: 2017 source edit |
||
(3 intermediate revisions by one other user not shown) | |||
Line 1: | Line 1: | ||
{{Featurepage|featured= | {{Featurepage|featured=false|featuredesc=Current Security Advisory: BSSA-2023-01|featurestart=07/26/2023}} | ||
{| class="wikitable" | {| class="wikitable" | ||
|+ | |+ | ||
Line 6: | Line 6: | ||
|- | |- | ||
|Date | |Date | ||
|2023- | |2023-10-30 | ||
|- | |- | ||
|Severity | |Severity | ||
| | |Low | ||
|- | |- | ||
|Affected | |Affected | ||
| | | | ||
* | * BlueSpiceAvatars | ||
|- | |- | ||
|Fixed in | |Fixed in | ||
| | | | ||
* | * BlueSpiceAvatars 4.3.3 | ||
* BlueSpiceAvatars 3.2.10.1 | |||
|- | |- | ||
|CVE | |CVE | ||
|[https://www.cve.org/ | |[https://www.cve.org/cverecord?id=CVE-2023-42431 CVE-2023-42431] | ||
|} | |} | ||
== Problem == | == Problem == | ||
When setting the avatar profile image, one can cause an XSS attack by inserting a modified URL in the dialog. The issue only occurs in the dialog itself and only in the context of the user that applied the change. | |||
== Solution == | == Solution == | ||
* BlueSpice 4: Update to version 4.3.3 | |||
* BlueSpice 3: Update Extension:BlueSpiceAvatars version [https://github.com/wikimedia/mediawiki-extensions-BlueSpiceAvatars/tree/3.2.10.1 3.2.10.1] | |||
== Acknowledgements == | == Acknowledgements == | ||
Special thanks to the security team of an undisclosed customer. |
Latest revision as of 12:45, 5 July 2024
Date | 2023-10-30 |
Severity | Low |
Affected |
|
Fixed in |
|
CVE | CVE-2023-42431 |
Problem
When setting the avatar profile image, one can cause an XSS attack by inserting a modified URL in the dialog. The issue only occurs in the dialog itself and only in the context of the user that applied the change.
Solution
- BlueSpice 4: Update to version 4.3.3
- BlueSpice 3: Update Extension:BlueSpiceAvatars version 3.2.10.1
Acknowledgements
Special thanks to the security team of an undisclosed customer.