CVE-2017-11737

NameCVE-2017-11737
Descriptioninterface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rspamd (PTS)buster1.8.1-2fixed
bullseye2.7-1fixed
bookworm3.4-1fixed
sid, trixie3.8.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rspamdsourcejessie(not affected)
rspamdsource(unstable)1.7.6-1

Notes

[jessie] - rspamd <not-affected> (Vulnerable code not present)
https://github.com/vstakhov/rspamd/issues/1738
https://github.com/rspamd/rspamd/pull/1739

Search for package or bug name: Reporting problems