CVE-2014-0141: XSS
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
Other sources
Jan Hutař of Red Hat reports:
When I create environment with HTML (like '<script>alert("hello")</script>') in name is not escaped properly on some pages when printing it and so might mean XSS attack possibility.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0141?
CVE-2014-0141 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-0141?
To fix CVE-2014-0141, ensure that proper input validation and output encoding are implemented to prevent the execution of malicious scripts.
What versions of Red Hat Satellite are affected by CVE-2014-0141?
CVE-2014-0141 specifically affects Red Hat Satellite version 6.0.3.
What type of attack is possible due to CVE-2014-0141?
CVE-2014-0141 allows for a potential cross-site scripting (XSS) attack due to improper escaping of HTML input.
Who reported the CVE-2014-0141 vulnerability?
The CVE-2014-0141 vulnerability was reported by Jan Hutař of Red Hat.