Project

General

Profile

Actions

Bug #2488

closed

Improved user input validation

Added by Alexander Watzinger 11 months ago. Updated 9 months ago.

Status:
Closed
Priority:
Normal
Category:
Backend
Target version:
Start date:
2025-02-21
Estimated time:
Found in version:

Description

INCIBE, the Spanish National Cybersecurity Institute, kindly made us aware of possible vulnerabilities reported by Andrea Intilangelo related to user input validation yesterday.
Most likely these were introduced unintentionally at recent system wide refactoring.

These vulnerabilities were not very serious/practical in the way OpenAtlas is used: a registered user with right access could have injected JavaScript via form fields. But a user with right access could wreck havoc anyway, that's what backups are for. Nevertheless we of course fixed these issues immediately and released them today with 8.10.1.

Thanks to Andrea Intilangelo and INCIBE for making us aware of it.

Actions #2

Updated by Alexander Watzinger 9 months ago

  • Description updated (diff)
Actions

Also available in: Atom PDF