CVE-2014-3653: XSS
A cross-site scripting (XSS) flaw was reported in Foreman's template preview screen. If a user were tricked into viewing a malicious template, it would lead to cross-site scripting attacks. Note that templates are commonly shared among users.
This issue was reported in version 1.6.0; however, older versions may also be vulnerable.
Upstream fix:
https://github.com/theforeman/foreman/pull/1778
References:
http://projects.theforeman.org/issues/7483
Other sources
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3653?
CVE-2014-3653 is classified as a Medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-3653?
To fix CVE-2014-3653, upgrade Foreman to version 1.6.1 or later.
What type of vulnerability is CVE-2014-3653?
CVE-2014-3653 is a cross-site scripting (XSS) vulnerability.
Which versions of Foreman are affected by CVE-2014-3653?
CVE-2014-3653 affects Foreman versions prior to 1.6.1.
Who can exploit CVE-2014-3653?
Remote attackers can exploit CVE-2014-3653 by injecting arbitrary web scripts or HTML through crafted provisioning templates.