*** This bug is a security vulnerability ***

Public security bug reported:

The shibboleth_login_form function in shibboleth.php in the Shibboleth
plugin before 1.8 for WordPress is prone to an XSS vulnerability due to
improper use of add_query_arg().

This has been fixed upstream here:
https://github.com/michaelryanmcneill/shibboleth/commit/1d65ad6786282d23ba1865f56e2fd19188e7c26a

** Affects: wordpress-shibboleth (Ubuntu)
     Importance: Medium
     Assignee: Simon Quigley (tsimonq2)
         Status: Fix Committed

** Affects: wordpress-shibboleth (Ubuntu Trusty)
     Importance: Medium
     Assignee: Simon Quigley (tsimonq2)
         Status: In Progress

** Affects: wordpress-shibboleth (Ubuntu Xenial)
     Importance: Medium
     Assignee: Simon Quigley (tsimonq2)
         Status: In Progress

** Affects: wordpress-shibboleth (Ubuntu Zesty)
     Importance: Medium
     Assignee: Simon Quigley (tsimonq2)
         Status: In Progress

** Affects: wordpress-shibboleth (Ubuntu Artful)
     Importance: Medium
     Assignee: Simon Quigley (tsimonq2)
         Status: Fix Committed

** Also affects: wordpress-shibboleth (Ubuntu Zesty)
   Importance: Undecided
       Status: New

** Also affects: wordpress-shibboleth (Ubuntu Trusty)
   Importance: Undecided
       Status: New

** Also affects: wordpress-shibboleth (Ubuntu Artful)
   Importance: Medium
     Assignee: Simon Quigley (tsimonq2)
       Status: In Progress

** Also affects: wordpress-shibboleth (Ubuntu Xenial)
   Importance: Undecided
       Status: New

** Changed in: wordpress-shibboleth (Ubuntu Trusty)
     Assignee: (unassigned) => Simon Quigley (tsimonq2)

** Changed in: wordpress-shibboleth (Ubuntu Xenial)
     Assignee: (unassigned) => Simon Quigley (tsimonq2)

** Changed in: wordpress-shibboleth (Ubuntu Zesty)
     Assignee: (unassigned) => Simon Quigley (tsimonq2)

** Changed in: wordpress-shibboleth (Ubuntu Zesty)
   Importance: Undecided => Medium

** Changed in: wordpress-shibboleth (Ubuntu Xenial)
   Importance: Undecided => Medium

** Changed in: wordpress-shibboleth (Ubuntu Trusty)
   Importance: Undecided => Medium

** Changed in: wordpress-shibboleth (Ubuntu Zesty)
       Status: New => In Progress

** Changed in: wordpress-shibboleth (Ubuntu Xenial)
       Status: New => In Progress

** Changed in: wordpress-shibboleth (Ubuntu Trusty)
       Status: New => In Progress

** Changed in: wordpress-shibboleth (Ubuntu Artful)
       Status: In Progress => Fix Committed

** Changed in: wordpress-shibboleth (Ubuntu Trusty)
    Milestone: None => trusty-updates

** Changed in: wordpress-shibboleth (Ubuntu Xenial)
    Milestone: None => xenial-updates

** Changed in: wordpress-shibboleth (Ubuntu Zesty)
    Milestone: None => zesty-updates

** Changed in: wordpress-shibboleth (Ubuntu Artful)
    Milestone: None => ubuntu-17.09

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-14313

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1718571

Title:
  [CVE] XSS security flaw due to add_query_arg

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/wordpress-shibboleth/+bug/1718571/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to