Author: buildbot
Date: Thu May 18 23:35:59 2017
New Revision: 1012498
Log:
Staging update by buildbot for juddi
Modified:
websites/staging/juddi/trunk/content/ (props changed)
websites/staging/juddi/trunk/content/security.html
Propchange: websites/staging/juddi/trunk/content/
------------------------------------------------------------------------------
--- cms:source-revision (original)
+++ cms:source-revision Thu May 18 23:35:59 2017
@@ -1 +1 @@
-1795571
+1795572
Modified: websites/staging/juddi/trunk/content/security.html
==============================================================================
--- websites/staging/juddi/trunk/content/security.html (original)
+++ websites/staging/juddi/trunk/content/security.html Thu May 18 23:35:59 2017
@@ -173,7 +173,7 @@
h2:hover > .headerlink, h3:hover > .headerlink, h1:hover > .headerlink,
h6:hover > .headerlink, h4:hover > .headerlink, h5:hover > .headerlink,
dt:hover > .elementid-permalink { visibility: visible }</style>
<h2 id="security-advisories-for-apache-juddi">Security Advisories for Apache
jUDDI<a class="headerlink" href="#security-advisories-for-apache-juddi"
title="Permanent link">¶</a></h2>
<h3 id="cveidcve-2015-5241">CVEID:CVE-2015-5241<a class="headerlink"
href="#cveidcve-2015-5241" title="Permanent link">¶</a></h3>
-<p>VERSION: 3.1.2, 3.1.3, 3.1.4, and 3.1.5 utilize the portlets based user
interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or
'uddi-console'</p>
+<p>VERSION: 3.1.2, 3.1.3, 3.1.4, and 3.1.5 that utilize the portlets based
user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or
'uddi-console'</p>
<p>PROBLEMTYPE: Open Redirect</p>
<p>REFERENCES: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5241</p>
<p>DESCRIPTION: After logging into the portal, the logout jsp page redirects
the browser back to the login page after. It is feasible for malicious user to
redirect the browser to an unintended web page. User session data, credentials,
and auth tokens are cleared before the redirect.</p>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]