CVE-2015-5282: XSS
A vulnerability allowing XSS in Foreman 1.7.0 and higher was reported from upstream. It is allowed to store the key/value parameters globally or assigned to various objects and using a tickbox in the UI the values can be hidden to mask them from casual viewing. The tickbox that hides/shows the value fails to handle HTML properly and so is vulnerable to an XSS issue where HTML can be stored in a parameter, and executed by another user if they later tick the hide/show box.
Upstream bug:
http://projects.theforeman.org/issues/11859
Other sources
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5282?
The severity of CVE-2015-5282 is classified as moderate.
How do I fix CVE-2015-5282?
To fix CVE-2015-5282, upgrade to Foreman version 1.10.0 or later.
What software is affected by CVE-2015-5282?
CVE-2015-5282 affects Foreman versions from 1.7.0 to 1.10.0, including many minor versions in between.
Does CVE-2015-5282 affect previous versions of Foreman?
Yes, CVE-2015-5282 affects all versions of Foreman from 1.7.0 up to and including 1.10.0.
Is CVE-2015-5282 an XSS vulnerability?
Yes, CVE-2015-5282 is a stored Cross-Site Scripting (XSS) vulnerability.