First published: Wed Aug 01 2018(Updated: )
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a user is linked directly to this URL.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Foreman | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-8634 is medium with a CVSS score of 5.4.
The vulnerability CVE-2016-8634 occurs when creating an organization or location in Foreman and using a name that contains HTML, which allows for a stored XSS attack.
The affected software of CVE-2016-8634 is Foreman 1.14.0.
To fix the vulnerability CVE-2016-8634, you should upgrade to a version of Foreman that is not affected.
You can find more information about CVE-2016-8634 on the following references: http://www.securityfocus.com/bid/94206, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8634, https://projects.theforeman.org/issues/17195.