CVE-2014-0089: XSS
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
Other sources
Jeremy Choi and Keqin Hong of the Red Hat HSS Pen-Test Team reported a stored XSS issue in foreman. Authenticated users who are able to add bookmarks may inject malicious javascript or html that will be executed by other users viewing the page.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0089?
CVE-2014-0089 is classified as a medium severity vulnerability due to its ability to allow authenticated users to inject malicious scripts.
How do I fix CVE-2014-0089?
To fix CVE-2014-0089, update Foreman to version 1.4.2 or later that addresses the XSS vulnerability.
Who reported the CVE-2014-0089 vulnerability?
CVE-2014-0089 was reported by Jeremy Choi and Keqin Hong of the Red Hat HSS Pen-Test Team.
In which versions of Foreman does CVE-2014-0089 affect?
CVE-2014-0089 affects Foreman versions 1.4.0 and 1.4.1.
What type of vulnerability is CVE-2014-0089?
CVE-2014-0089 is a cross-site scripting (XSS) vulnerability.