REDHAT-BUG-523277: Medium severity prototype vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-7220 to the following vulnerability:
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
References: ------------ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220 http://github.com/sstephenson/prototype/blob/master/CHANGELOG http://osvdb.org/46312
Upstream patch: --------------- git clone git://github.com/sstephenson/prototype.git git show 02cc9992e915c024650ddc77a91064f7a4252914
The relevant file in WordPress source rpm package (F10) is: ------------------------------------------------------------ BUILD/wordpress/wp-includes/js/prototype.js
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-523277?
The severity of REDHAT-BUG-523277 is considered high due to the unspecified vulnerability that may allow cross-site scripting attacks.
How do I fix REDHAT-BUG-523277?
To fix REDHAT-BUG-523277, update the Prototype JavaScript framework to version 1.6.0.2 or later.
What products are affected by REDHAT-BUG-523277?
The affected product for REDHAT-BUG-523277 is the Prototype JavaScript framework versions before 1.6.0.2.
What types of attacks can REDHAT-BUG-523277 facilitate?
REDHAT-BUG-523277 can facilitate cross-site scripting attacks that compromise the security of web applications.
When was REDHAT-BUG-523277 disclosed?
REDHAT-BUG-523277 was disclosed due to the vulnerabilities found in the Prototype JavaScript framework prior to version 1.6.0.2.