Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.

Bug 402013

Summary: Found xss on bugs.eclipse.org/bugs
Product: Community Reporter: sid sol <thesiddharthsolanki>
Component: BugzillaAssignee: Eclipse Webmaster <webmaster>
Status: RESOLVED FIXED QA Contact:
Severity: critical    
Priority: P3 CC: thatnitind, wayne.beaton
Version: unspecified   
Target Milestone: ---   
Hardware: PC   
OS: Windows 7   
Whiteboard:

Description sid sol CLA 2013-02-28 09:36:29 EST
Hello recently i was browsing bugs.eclipse.org/bugs then i have found the xss on 

https://bugs.eclipse.org/bugs/show_bug.cgi?id=382972%22%3E%3Cimg%20src=%22aaa.jpg%22%20onerror=javascript:alert%28%27Xss%27%29%3E&format=123

So i hope this much info will help you to make eclipse more secure !!
regards
siddharth
Comment 1 Wayne Beaton CLA 2013-02-28 14:20:06 EST
Moving to Bugzilla component and marking as "committer-only" to avoid widespread dissemination until after we've resolved the issue.
Comment 2 Denis Roy CLA 2013-02-28 14:28:27 EST
This was recently "fixed" my Mozilla last week.

https://bugzilla.mozilla.org/show_bug.cgi?id=842038

But thanks to the Bugzilla's (IMO, absurd) policy of opening security bugs to the world the minute they have a patch, well, that leaves us vulnerable.
Comment 3 Frédéric Buclin CLA 2013-02-28 18:05:14 EST
(In reply to comment #2)
> This was recently "fixed" my Mozilla last week.

I don't know why you quoted "fixed". It's fixed. Period.


> But thanks to the Bugzilla's (IMO, absurd) policy of opening security bugs
> to the world the minute they have a patch, well, that leaves us vulnerable.

I don't know how well you speak Perl, but it wouldn't take very long for a hacker to understand what the patch is about simply by reading it. Security by obscurity is a weak way to protect yourself. If you expected to stay "secure" simply by not disclosing the vulnerability, then you loose for sure.
Comment 4 Denis Roy CLA 2013-02-28 20:09:46 EST
> Security
> by obscurity is a weak way to protect yourself. If you expected to stay
> "secure" simply by not disclosing the vulnerability, then you loose for sure.

But you've also disclosed the exploit.  That is the point you can't seem to comprehend.

I have absolutely no desire to discuss this with you further.  I've expressed my opinion clearly here and in the Mozilla bug, and I've offered what I consider to be constructive criticis

For everyone else, I will upgrade Bugzilla tomorrow.
Comment 5 Denis Roy CLA 2013-03-01 10:41:13 EST
Bugzilla is running 4.2.5 now.