CVE-2014-3531: XSS
It was found [1] that Red Hat Satellite 6 WebUI has a bug which allows an authenticated user to perform an XSS attack.
[1]: https://bugzilla.redhat.com/showbug.cgi?id=1106417
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3531?
CVE-2014-3531 has a moderate severity level due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2014-3531?
To mitigate CVE-2014-3531, users should update to the latest version of TheForeman that addresses this vulnerability.
Who is affected by CVE-2014-3531?
CVE-2014-3531 affects authenticated users of the Red Hat Satellite 6 WebUI that runs version 1.5.1 or lower of TheForeman.
What type of vulnerability is CVE-2014-3531?
CVE-2014-3531 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2014-3531 be exploited remotely?
No, CVE-2014-3531 requires user authentication, limiting its exploitation to logged-in users.