#1088610 cups: XSS vulnerability in web interface not backported

Package:
cups
Source:
cups
Description:
Common UNIX Printing System(tm) - PPD/driver support, web interface
Submitter:
Josia
Date:
2024-11-28 14:15:02 UTC
Severity:
normal
Tags:
#1088610#5
Date:
2024-11-28 14:08:37 UTC
From:
To:
Hello Debian Printing Team,

version 2.4.2 of cups contains an XSS vulnerability that was fixed in commit
988ddfd[0] and published in release v2.4.8[1].

Exploitation is trivial:
"https://localhost:631/admin?DEBUG_LOGGING=onfocus=alert(1) autofocus="

However, no CVE was assigned, so no one backported this patch to
2.4.2-3+deb12u8.

The vulnerability was detected by Tenable, which performs various fuzzing
scans.

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
     ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these template lines ***

[0]
https://github.com/OpenPrinting/cups/commit/988ddfd9e66affdb4ed8714c30de96fb304ef4cb
[1] https://github.com/OpenPrinting/cups/releases/tag/v2.4.8