Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-24419

XSS attack in Ambari Config History

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Critical
    • Resolution: Unresolved
    • 2.7.1
    • None
    • ambari-client
    • None

    Description

      It is possible for an attacker to steal information or access from users by executing malicious JavaScript. This is possible due to the use of a javascript "eval()" function when loading the notes from config history change. Leveraging this one user could create a malicious history entry to steal access or information of another user. Upon viewing the malicious historical entry the victim would be comprimised by directly scraping any information on the page, modify its appearance, or having their session information stolen.

       

       

       

       

      fg

       

       

       

      Attachments

        Activity

          People

            rlevas Robert Levas
            juliaw Julia Wang
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated: