Regarding Cross-site Scripting Vulnerability in Pleasanter
Release date: May 25, 2023
■Overview
It has been discovered that all versions of our product "Pleasanter" are vulnerable to cross-site scripting. If this vulnerability is exploited, there is a risk that malicious third parties may redirect users to external fraudulent sites or leak or tamper with data registered in Pleasanter.
The versions of Pleasanter affected by this issue are listed below. Please take the measures listed in the countermeasures.
■How to check the affected version
The affected versions are as follows:
All versions prior to 1.3.38.1
*Apply to both Community Edition and Enterprise Edition.
*This also applies to versions 1.2, 1.1, 0.51, 0.50, 0.49 and earlier.
Please refer to the following user manual for how to check the version.
"FAQ: How do I check the version of Pleasanter?"
https://pleasanter.org/manual/faq-version
■Vulnerability description
There is a vulnerability that allows a logged-in general user to embed a script in a special notation method in columns that can be entered in Markdown format (content, explanation, comments, etc.), which can lead to external sites or executing scripts provided by Pleasanter. Anonymous users who cannot log in to Pleasanter cannot use this vulnerability to carry out attacks.
■Threat posed by vulnerabilities
Scripts installed by attackers may redirect users to malicious external sites. In addition, if a Pleasanter manager opens a page where an attacker has installed a script, they may be forced to unintentionally perform administrative operations on Pleasanter.
■Countermeasure
For customers using version 1.3.X
Please upgrade to the latest fixed version, 1.3.38.2 or later (released on May 25, 2023). If you want to avoid upgrading, please apply the individual patch published in the "Temporary Workaround" section.
For customers using versions 1.2.X, 1.1.X, 0.51.X, 0.50.X, 0.49.X or earlier
Please upgrade to the latest version 1.3.38.2 or later (released on May 25, 2023), which has been fixed. If you want to avoid upgrading, customers with annual support contracts can contact the support desk to receive an individual patch tailored to their version. For more information, please contact the support desk.
In addition, customers who do not have an annual support service contract should upgrade to version 1.3.38.2. If you want to avoid upgrading, please sign up for the annual support service and contact us at the "Contact Information" below to receive an individual patch.
■Temporary measures
For customers using version 1.3.X
Please download the individual patches below.
https://github.com/Implem/Implem.Pleasanter/issues/474
[Note] If you upgrade to Pleasanter 1.3.38.2 or later after applying this individual patch, please delete this individual patch.
For customers using versions 1.2.X, 1.1.X, 0.51.X, 0.50.X, 0.49.X or earlier
Please contact us via the support website. (Annual support contract required)
■Change log
2023.5.25 This vulnerability has been made public.
■Contact information
If you have any questions regarding this matter, please contact us using the information below.