Exaoperation Monitoring page vulnerable to XSS attack
Details
| Detail name | Value |
|---|---|
| Changelog Number | 10940 |
| Type | Bug |
| Status | Resolved |
| Affected Versions | EXASOL 6.0.0, Exasol 6.1.0, Exasol 6.2.0, Exasol 7.0.0 |
| Fix Versions | Exasol 7.1.0, Exasol 7.0.4, Exasol 6.1.14, Exasol 6.2.12 |
| Resolution Date | 2020-11-26 |
Issue
We identified a critical XSS (cross-site-scripting) vulnerability in Exaoperation's Monitoring page. An unauthenticated attacker with network access to Exaoperation can exploit this to gain access to Exaoperation with the privileges of a logged-in user that visits the Monitoring page.
Remediation
Users should upgrade to Exasol version 6.1.14, 6.2.12 or 7.0.4
As a workaround or if the fix cannot be applied, one can avoid executing malicious code by not clicking on any logservice on the EXAoperation Monitoring page. The generated logs can be forwarded to a remote syslog server as described in the documentation by editing the logservice.