CVE-2014-3491: XSS
Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3491?
CVE-2014-3491 is classified as a medium severity vulnerability due to its potential impact on application security through cross-site scripting.
How do I fix CVE-2014-3491?
To fix CVE-2014-3491, upgrade to Foreman version 1.4.5 or 1.5.1 and above, which contain the necessary patches.
What types of software are affected by CVE-2014-3491?
CVE-2014-3491 affects Foreman versions prior to 1.4.5 and versions in the 1.5.x series prior to 1.5.1.
What kind of attacks can CVE-2014-3491 facilitate?
CVE-2014-3491 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Is there a specific component in Foreman that is vulnerable due to CVE-2014-3491?
The vulnerability in CVE-2014-3491 specifically affects the New Host groups page, particularly the Name field used in create, update, and destroy notification boxes.