Fedora 19 : ReviewBoard-1.7.18-1.fc19 / python-djblets-0.7.23-1.fc19 (2013-20814)

medium Nessus Plugin ID 70931

Synopsis

The remote Fedora host is missing one or more security updates.

Description

1.7.18 fixes JavaScript errors

- New upstream security release 1.7.17

- http://www.reviewboard.org/docs/releasenotes/reviewboa rd/1.7.17/

- Resolves: CVE-2013-4519

- Security Fixes :

- Fixed XSS vulnerabilities for the 'Branch' field and uploaded file captions.

- Added a 'X-Frame-Options' header to prevent clickjacking.

- New Features :

- Remove the need for SSH keys for GitHub repositories.

- Improved validation for GitHub repositories.

- Added support for permissions on Local Sites.

- Performance Improvements :

- Reduced query counts on all pages.

- Reduced query counts in the web API when returning empty lists.

- Extensibility :

- Extensions using the ``configure_extension`` view an now pass in a custom ``template_name`` pointing to a template for the configuration page, if it needs additional customization.

- Enabling, disabling or reconfiguring extensions will now invalidate the caches for pages, ensuring that hooks will take affect.

- Extension configuration now works properly on subdirectory installs.

- Bug Fixes :

- Fixed showing private review requests on a submitter page.

- The description for submitted or discarded review requests is now shown on the diff viewer.

- Discarding, reopening and then closing a review request no longer makes the review request private.

- Fixed a naming conflict with older PyCrypto packages, such as the default package on CentOS 6.4.

- Users with the 'can_change_status' permission no longer need the 'can_edit_reviewrequest' permission in order to close or reopen review requests.

- Switching a repository from using a hosting service to Custom no longer reverts back to the hosting service.

- Fixed editing a repository if its associated hosting service can't be loaded (such as if an extension providing that hosting service is disabled).

- Many diff validation errors weren't being shown on the New Review Request page, generating 500 errors instead.

- Fixed caching issues with the Blocks field on review requests.

- Editing JSON text fields in the administration UI now works, validates, and won't result in warnings in the log.

- Fixed breakages with looking up URLs internally with Local Sites.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected ReviewBoard and / or python-djblets packages.

See Also

https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.17/

https://bugzilla.redhat.com/show_bug.cgi?id=1027010

http://www.nessus.org/u?96b95434

http://www.nessus.org/u?5f4c3db4

Plugin Details

Severity: Medium

ID: 70931

File Name: fedora_2013-20814.nasl

Version: 1.10

Type: local

Agent: unix

Published: 11/18/2013

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:reviewboard, p-cpe:/a:fedoraproject:fedora:python-djblets, cpe:/o:fedoraproject:fedora:19

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 11/7/2013

Vulnerability Publication Date: 11/18/2013

Reference Information

CVE: CVE-2013-4519

BID: 63601

FEDORA: 2013-20814