ryzom / ryzomcore

Ryzom Core is the open-source project related to the Ryzom game. This community repository is synchronized with the Ryzom Forge repository, based on the Core branch.
https://wiki.ryzom.dev
GNU Affero General Public License v3.0
330 stars 89 forks source link

Remote code execution vulnerability in the client #328

Closed ryzom-pipeline closed 6 years ago

ryzom-pipeline commented 6 years ago

Original report by Wladimir Palant (Bitbucket: palant, GitHub: palant).


I've sent the details of this security issue to support@ryzom.com on May 15, this approach has been suggested by a gamemaster. So far I didn't get any reply whatsoever. Has my information been forwarded to the developers? Is it being worked on? What's the timeline? Or is there a better way to share information with developers that doesn't belong into a public issue report?

ryzom-pipeline commented 6 years ago

Original comment by Meelis Mägi (Bitbucket: [Meelis Mägi](https://bitbucket.org/Meelis Mägi), ).


You can send that info to me nimetu-ryzom-com address

ryzom-pipeline commented 6 years ago

Original comment by Wladimir Palant (Bitbucket: palant, GitHub: palant).


Done.

ryzom-pipeline commented 6 years ago

Original comment by Wladimir Palant (Bitbucket: palant, GitHub: palant).


According to Meelis Mägi, the issue is resolved. I published the overview under https://palant.de/2018/05/18/ryzom-falling-remote-code-execution-via-the-in-game-browser

ryzom-pipeline commented 6 years ago

Original comment by Meelis Mägi (Bitbucket: [Meelis Mägi](https://bitbucket.org/Meelis Mägi), ).


this issue is with webapp xss (resolved) and not with client