CVE-2016-8634: XSS
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a user is linked directly to this URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8634?
The severity of CVE-2016-8634 is medium with a CVSS score of 5.4.
How does the vulnerability CVE-2016-8634 occur?
The vulnerability CVE-2016-8634 occurs when creating an organization or location in Foreman and using a name that contains HTML, which allows for a stored XSS attack.
What is the affected software of CVE-2016-8634?
The affected software of CVE-2016-8634 is Foreman 1.14.0.
How can I fix the vulnerability CVE-2016-8634?
To fix the vulnerability CVE-2016-8634, you should upgrade to a version of Foreman that is not affected.
Where can I find more information about CVE-2016-8634?
You can find more information about CVE-2016-8634 on the following references: http://www.securityfocus.com/bid/94206, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8634, https://projects.theforeman.org/issues/17195.