CVE-2014-0183: XSS
Published Jan 2, 2020
·Updated
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
Affected Software
1 affected component
redhat Subscription Asset Manager=1.4.0
Event History
Jan 2, 2020
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2014-0183.
2
What is the severity of CVE-2014-0183?
The severity of CVE-2014-0183 is medium.
3
Which software versions are affected by CVE-2014-0183?
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are affected by CVE-2014-0183.
4
What is the CWE ID of CVE-2014-0183?
The CWE ID of CVE-2014-0183 is 79.
5
How can I fix the vulnerability CVE-2014-0183?
To fix the vulnerability CVE-2014-0183, update Katello to a version that is not affected by this vulnerability.