First published: Sat Jul 26 2014(Updated: )
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Technology Resin | <=4.0.39 | |
Caucho Technology Resin | =4.0.36 | |
Caucho Technology Resin | =4.0.37 | |
Caucho Technology Resin | =4.0.38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2966 is considered a medium severity vulnerability due to its potential to allow remote attackers to bypass text restrictions.
To fix CVE-2014-2966, upgrade to Resin Pro version 4.0.40 or later, where the Unicode transformation issue has been addressed.
CVE-2014-2966 affects Resin Pro versions prior to 4.0.40, specifically versions 4.0.36, 4.0.37, 4.0.38, and 4.0.39.
An attacker exploiting CVE-2014-2966 can craft characters that allow them to bypass intended text restrictions, potentially leading to XSS attacks.
Yes, CVE-2014-2966 specifically allows attackers to bypass XSS protection mechanisms due to improper Unicode transformations.