OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to create commits with filenames that included HTML code that was injected in the page without proper sanitation. This allowed a persisted XSS attack against all members of this project that accessed the repositories page to display a changeset where the maliciously crafted file was deleted. Versions 16.6.9, 17.0.6, 17.1.3, and 17.2.1 fix the issue.
An attacker with write permissions (push access) to a repository creates a commit containing a file whose name includes malicious HTML or JavaScript code. The Repositories module, when displaying the changeset, does not properly escape file names, allowing the embedded code to reach the page without proper sanitization. The malicious script is executed in the browser context of every user who views the repositories page containing the changeset with the deleted, crafted file. This is a persisted (stored) XSS attack, meaning the payload is permanently stored on the server side and activated each time the page is accessed.
An attacker can execute arbitrary JavaScript code in the context of a logged-in user's session, which may lead to theft of session tokens, credentials, and execution of unauthorized actions on behalf of the victim in the OpenProject application. Due to the scope change (Scope:Changed), the attack may also affect resources outside the directly controlled application.
OpenProject should be updated to version 16.6.9, 17.0.6, 17.1.3 or 17.2.1 depending on the branch in use. Until an update is applied, consider restricting push access permissions in repositories to trusted users only and limiting access to the Repositories module. Details are available in the official security advisory: https://github.com/opf/openproject/security/advisories/GHSA-p423-72h4-fjvp
OpenProject versions prior to 16.6.9 (16.x branch), 17.0.6 (17.0.x branch), 17.1.3 (17.1.x branch) and 17.2.1 (17.2.x branch) with the Repositories module enabled.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HOpenproject
APPOpenproject17.2.0< 16.6.917.0.0 – 17.0.6 (excl.)17.1.0 – 17.1.3 (excl.)
Related vulnerabilities
SQL Injection w OpenProject — operator =n bez parametryzacji zapytań
SQL Injection w OpenProject umożliwiający zdalne wykonanie kodu Ruby
OpenProject: command injection w endpointcie repozytorium prowadzący do RCE
OpenProject: command injection w endpoincie diff repozytorium (zapis dowolnych plików)
OpenProject — odczyt lokalnych plików przez SVG/ImageMagick przy eksporcie PDF