First published: Tue May 06 2014(Updated: )
<a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=1088315">bug 1088315</a> Users can create malicious key names containing script tags. They are executed by other users via the autocomplete function when searching for keys. See: <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=1088315">https://bugzilla.redhat.com/show_bug.cgi?id=1088315</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Foreman | <=1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.