Executive brief
A vulnerability exists in the OpenStack Puppet module for Gerrit, a tool used for code reviews and source code management. The module incorrectly configures Gerrit to treat HTML files as safe, which allows an attacker to create a malicious code review that executes scripts in the browser of anyone who views it. This could lead to the theft of account information or unauthorized actions performed on behalf of the victim.
Technical details
The vulnerability is a Cross-Site Scripting (XSS) flaw (CWE-79) caused by an insecure default configuration in the puppet-gerrit module. Specifically, the 'gerrit.config.erb' template explicitly marked 'text/html' as a safe mimetype. When this setting is enabled, Gerrit renders HTML files directly in the browser instead of downloading them. An unauthenticated remote attacker can exploit this by submitting a crafted code review containing malicious HTML/JavaScript. If a user views the review at a specific URL, the script executes in their browser context, potentially allowing the attacker to access sensitive account information or session tokens. The issue was addressed by removing the 'text/html' safe mimetype entry from the configuration template.
Affected products
- OpenStack puppet-gerrit -
Timeline
- 2016-06-22: disclosed: Vulnerability discussed on oss-security mailing list
- 2016-06-22: patched: Fix committed to puppet-gerrit repository
- 2017-01-12: advisory: NVD publication date