Actions
Bug #17006
closed
JP
JP
Potential XSS via rule descriptions in the Suricata Blocks page
Bug #17006:
Potential XSS via rule descriptions in the Suricata Blocks page
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:
Description
The Suricata Blocks page at suricata_blocked.php does not encode rule descriptions or other block data before display.
The rule descriptions can be supplied by custom rules or untrusted external sources which could contain a problematic payload potentially leading to XSS.
For example:
alert icmp any any -> any any (msg:"xss<img src=x onerror=alert(String.fromCharCode(88,83,83))>"; itype:8; sid:990064640; rev:1;)
If the attacker then sends traffic matching the rule while Suricata is set to block, then the next admin to view the Blocks page would trigger an XSS.
Reported by: @lujiefsi
JP Updated by Jim Pingle about 1 month ago
- Subject changed from Suricata: Potential XSS via Blocks page rule descriptions to Potential XSS via rule descriptions in the Suricata Blocks page
JP Updated by Jim Pingle about 1 month ago
- Description updated (diff)
JP Updated by Jim Pingle about 1 month ago
- Status changed from Confirmed to Feedback
- % Done changed from 0 to 100
- Private changed from Yes to No
Fixed in Suricata pkg v7.0.9
GT Updated by Georgiy Tyutyunnik 28 days ago
- Status changed from Feedback to Resolved
Fixed in Suricata pkg v7.0.9, available in 26.03.1 and 26.07
Actions