
julien at bestpractical
Feb 12, 2004, 1:53 PM
Views: 1290
Permalink
|
|
RTIR 1.0.4 now available - Fixes XSS vulnerability]
|
|
I'm pleased to announce that RT for Incident Response 1.0.4 is now available at: http://www.fsck.com/pub/rt/release/rtir-1-0-4.tar.gz This version fixes a cross-site scripting vulnerability reported on 9 February 2004. This issue, described in ticket #5249, involved the display of user-entered subject lines as non-escaped html. The issue is described in detail here (login as "guest" with password "guest"): http://rt3.fsck.com/Ticket/Display.html?id=5249 We strongly encourage all sites currently running RTIR to upgrade to this release. Many thanks to Vytautas Krakauskas from LitNET NOC CERT (vytautas [at] litnet) for reporting this XSS issue. This version of RTIR also features significant performance improvements, and the addition of the requestor in the main page listing of unlinked incident reports. Bug fixes include: - no HTML escaping on pre-populated information for new incidents and investigations - stealing an incident, incident report, investigation, or block produces the proper owner for all related tickets - 'About RTIR' link only appears when the user is inside of RTIR - The DutyTeam group receives ShowTemplate permissions by default, for easier use of the Scripted Action tool. Best, Linda Julien Best Practical _______________________________________________ rt-announce mailing list rt-announce [at] lists http://lists.bestpractical.com/mailman/listinfo/rt-announce
|