CVE-2014-0208: XSS
bug 1088315
Users can create malicious key names containing script tags. They are executed by other users via the autocomplete function when searching for keys.
See: https://bugzilla.redhat.com/showbug.cgi?id=1088315
Other sources
Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted key name.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0208?
CVE-2014-0208 is considered to be a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2014-0208?
To fix CVE-2014-0208, users should update their Foreman installations to versions later than 1.4.3.
What type of vulnerability is CVE-2014-0208?
CVE-2014-0208 is an XSS vulnerability that allows for the execution of malicious scripts in user-created key names.
Who is affected by CVE-2014-0208?
CVE-2014-0208 affects versions of Foreman up to and including 1.4.3, impacting users who utilize the autocomplete feature.
What are the consequences of CVE-2014-0208?
The consequences of CVE-2014-0208 include potential exposure to XSS attacks where malicious scripts could be executed in the context of other users.