Stored cross-site scripting in mod_cluster - CVE-2023-6710
Published: March 20, 2024 / Updated: October 25, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the "alias" parameter in he URL. A remote attacker can permanently inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Rational Build Forge
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
mod_jk (Red Hat package)
mod_proxy_cluster (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services
How to mitigate CVE-2023-6710
IBM Rational Build Forge - update to 8.0.0.26
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-35.el7jbcs, 0.4.10-35.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-20.el7jbcs, 1.0.0-20.el8jbcs
mod_jk (Red Hat package) - update to 1.2.49-1.el9_4
mod_proxy_cluster (Red Hat package) - update to 1.3.20-1.el9_4
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-3.el7jbcs, 1.3.20-3.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-104.el7jbcs, 1.6.1-104.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-36.el7jbcs, 1.15.19-36.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-4.el7jbcs, 2.4.24-4.el8jbcs
JBoss Core Services - update to 2.4.57 SP3
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-9.el7jbcs, 2.4.57-9.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-34.el7jbcs, 2.9.3-34.el8jbcs
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.6.0-3.el7jbcs, 8.6.0-3.el8jbcs
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Stored XSS in mod_cluster for Apache HTTP Server
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- Multiple vulnerabilities in IBM Rational Build Forge
- Red Hat Enterprise Linux 9 update for mod_jk and mod_proxy_cluster