Arch Linux 752 Published by

The following updates has been released for Arch Linux:

ASA-201908-21: grafana: denial of service
ASA-201908-22: jenkins: multiple issues



ASA-201908-21: grafana: denial of service

Arch Linux Security Advisory ASA-201908-21
==========================================

Severity: Medium
Date : 2019-08-30
CVE-ID : CVE-2019-15043
Package : grafana
Type : denial of service
Remote : Yes
Link : https://security.archlinux.org/AVG-1034

Summary
=======

The package grafana before version 6.3.4-1 is vulnerable to denial of
service.

Resolution
==========

Upgrade to 6.3.4-1.

# pacman -Syu "grafana>=6.3.4-1"

The problem has been fixed upstream in version 6.3.4.

Workaround
==========

None.

Description
===========

This vulnerability allows any unauthenticated user/client to access the
Grafana snapshot HTTP API and create a denial of service attack by
posting large amounts of dashboard snapshot payloads to the
/api/snapshotsHTTP API endpoint.

Impact
======

A remote attacker is able to cause a denial of service by sending a
specially crafted request.

References
==========

https://grafana.com/blog/2019/08/29/grafana-5.4.5-and-6.3.4-released-with-important-security-fix/
https://github.com/grafana/grafana/commit/be2e2330f5c1f92082841d7eb13c5583143963a4
https://security.archlinux.org/CVE-2019-15043

ASA-201908-22: jenkins: multiple issues

Arch Linux Security Advisory ASA-201908-22
==========================================

Severity: Medium
Date : 2019-08-30
CVE-ID : CVE-2019-10383 CVE-2019-10384
Package : jenkins
Type : multiple issues
Remote : Yes
Link : https://security.archlinux.org/AVG-1030

Summary
=======

The package jenkins before version 2.192-1 is vulnerable to multiple
issues including cross-site request forgery and cross-site scripting.

Resolution
==========

Upgrade to 2.192-1.

# pacman -Syu "jenkins>=2.192-1"

The problems have been fixed upstream in version 2.192.

Workaround
==========

None.

Description
===========

- CVE-2019-10383 (cross-site scripting)

Jenkins did not properly escape the update site URL in some status
messages shown in the update center, resulting in a stored cross-site
scripting vulnerability that is exploitable by administrators and
affects other administrators.

- CVE-2019-10384 (cross-site request forgery)

Jenkins allowed the creation of CSRF tokens without a corresponding web
session ID. This is the result of an incomplete fix for SECURITY-626 in
the 2019-07-17 security advisory. This allowed attackers able to obtain
a CSRF token without associated session ID to implement CSRF attacks
with the following constraints. The token had to be created for the
anonymous user (and could only be used for actions the anonymous user
can perform). The victim’s IP address needed to remain unchanged
(unless the proxy compatibility option was enabled) The victim must not
have a valid web session at the time of the attack. CSRF token
generation now creates a web session if none exists yet, so that the
lack of a web session ID cannot be exploited.

Impact
======

An attacker with administrative access can execute XSS attacks on other
administrators by using crafted status messages on the update center.
Further, an attacker is able to execute a CSRF attack under a very
narrow set of constraints.

References
==========

https://jenkins.io/security/advisory/2019-08-28/
https://security.archlinux.org/CVE-2019-10383
https://security.archlinux.org/CVE-2019-10384