Exaoperation Monitoring page vulnerable to XSS attack

Details

Detail name Value
Changelog Number 10940
Type Bug
Status Resolved
Affected Versions EXASOL 6.0.0, Exasol 6.1.0, Exasol 6.2.0, Exasol 7.0.0
Fix Versions Exasol 7.1.0, Exasol 7.0.4, Exasol 6.1.14, Exasol 6.2.12
Resolution Date 2020-11-26

Issue

We identified a critical XSS (cross-site-scripting) vulnerability in Exaoperation's Monitoring page. An unauthenticated attacker with network access to Exaoperation can exploit this to gain access to Exaoperation with the privileges of a logged-in user that visits the Monitoring page.

Remediation

Users should upgrade to Exasol version 6.1.14, 6.2.12 or 7.0.4
As a workaround or if the fix cannot be applied, one can avoid executing malicious code by not clicking on any logservice on the EXAoperation Monitoring page. The generated logs can be forwarded to a remote syslog server as described in the documentation by editing the logservice.