ID

VAR-201209-0151


CVE

CVE-2012-3551


TITLE

Crowbar of Crowbar barclamp Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2012-004100

DESCRIPTION

Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and earlier, allows remote attackers to inject arbitrary web script or HTML via the file parameter to /utils. Crowbar is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 1.98

sources: NVD: CVE-2012-3551 // JVNDB: JVNDB-2012-004100 // BID: 55315 // VULHUB: VHN-56832

AFFECTED PRODUCTS

vendor:dellmodel:crowbarscope:lteversion:1.4

Trust: 1.8

vendor:dellmodel:crowbarscope:eqversion:1.4

Trust: 0.6

sources: JVNDB: JVNDB-2012-004100 // CNNVD: CNNVD-201208-676 // NVD: CVE-2012-3551

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-3551
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-3551
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201208-676
value: MEDIUM

Trust: 0.6

VULHUB: VHN-56832
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-3551
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-56832
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-56832 // JVNDB: JVNDB-2012-004100 // CNNVD: CNNVD-201208-676 // NVD: CVE-2012-3551

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-56832 // JVNDB: JVNDB-2012-004100 // NVD: CVE-2012-3551

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201208-676

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201208-676

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-004100

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-56832

PATCH

title:SUSE-Cloud / barclamp-crowbar - remaining fix for html_escape file to avoid XSS (bnc#771840)url:https://github.com/SUSE-Cloud/barclamp-crowbar/commit/a82ed926c6e3ba2b0cada213c35e4b00f34ea629

Trust: 0.8

title:SUSE-Cloud / barclamp-crowbar - make sure to html_escape file to avoid XSS (bnc#771840)url:https://github.com/SUSE-Cloud/barclamp-crowbar/commit/90e905b7668a1cc884fb70040f96c7a0a287de48

Trust: 0.8

title:SUSE-Cloud / barclamp-deployerurl:https://github.com/SUSE-Cloud/barclamp-deployer/tree/

Trust: 0.8

title:dellcloudedge / crowbarurl:https://github.com/dellcloudedge/crowbar

Trust: 0.8

title:barclamp-crowbar-masterurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=44493

Trust: 0.6

sources: JVNDB: JVNDB-2012-004100 // CNNVD: CNNVD-201208-676

EXTERNAL IDS

db:NVDid:CVE-2012-3551

Trust: 2.8

db:BIDid:55315

Trust: 2.0

db:OPENWALLid:OSS-SECURITY/2012/08/31/1

Trust: 1.7

db:JVNDBid:JVNDB-2012-004100

Trust: 0.8

db:MLISTid:[OSS-SECURITY] 20120830 RE: CVE REQUEST: CROWBAR XSS

Trust: 0.6

db:CNNVDid:CNNVD-201208-676

Trust: 0.6

db:EXPLOIT-DBid:37690

Trust: 0.1

db:VULHUBid:VHN-56832

Trust: 0.1

sources: VULHUB: VHN-56832 // BID: 55315 // JVNDB: JVNDB-2012-004100 // CNNVD: CNNVD-201208-676 // NVD: CVE-2012-3551

REFERENCES

url:http://www.securityfocus.com/bid/55315

Trust: 1.7

url:https://bugzilla.novell.com/show_bug.cgi?id=771840

Trust: 1.7

url:https://github.com/suse-cloud/barclamp-crowbar/commit/90e905b7668a1cc884fb70040f96c7a0a287de48

Trust: 1.7

url:https://github.com/suse-cloud/barclamp-crowbar/commit/a82ed926c6e3ba2b0cada213c35e4b00f34ea629

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2012/08/31/1

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-3551

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-3551

Trust: 0.8

url:http://cloud.watch.impress.co.jp/docs/news/20120903_557204.html

Trust: 0.8

sources: VULHUB: VHN-56832 // JVNDB: JVNDB-2012-004100 // CNNVD: CNNVD-201208-676 // NVD: CVE-2012-3551

CREDITS

Matthias Weckbecker with SUSE.

Trust: 0.9

sources: BID: 55315 // CNNVD: CNNVD-201208-676

SOURCES

db:VULHUBid:VHN-56832
db:BIDid:55315
db:JVNDBid:JVNDB-2012-004100
db:CNNVDid:CNNVD-201208-676
db:NVDid:CVE-2012-3551

LAST UPDATE DATE

2025-04-11T23:14:49.045000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-56832date:2012-09-06T00:00:00
db:BIDid:55315date:2012-08-31T22:40:00
db:JVNDBid:JVNDB-2012-004100date:2012-09-07T00:00:00
db:CNNVDid:CNNVD-201208-676date:2012-09-03T00:00:00
db:NVDid:CVE-2012-3551date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-56832date:2012-09-05T00:00:00
db:BIDid:55315date:2012-08-30T00:00:00
db:JVNDBid:JVNDB-2012-004100date:2012-09-07T00:00:00
db:CNNVDid:CNNVD-201208-676date:2012-08-30T00:00:00
db:NVDid:CVE-2012-3551date:2012-09-05T23:55:02.600