CVE-2016-8639: XSS
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
Other sources
Sanket Jagtap of Red Hat reports:
If an organization or location is created with a name containing HTML, then the administrator-only Settings page will render the HTML as part of a dropdown menu.
This may permit a stored XSS attack if an organization/location with HTML in the name is created, then an administrator attempts to change the default organization/location settings.
Upstream bug:
http://projects.theforeman.org/issues/15037
Upstream patch:
https://github.com/theforeman/foreman/pull/3523
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8639?
CVE-2016-8639 is classified as a moderate severity vulnerability.
How do I fix CVE-2016-8639?
To fix CVE-2016-8639, upgrade to foreman version 1.13.0 or later.
Who is affected by CVE-2016-8639?
CVE-2016-8639 affects foreman versions before 1.13.0 and certain Red Hat Satellite versions.
What type of vulnerability is CVE-2016-8639?
CVE-2016-8639 is a stored cross-site scripting (XSS) vulnerability.
Can CVE-2016-8639 be exploited remotely?
Yes, CVE-2016-8639 can be exploited remotely by an attacker with privileges to set organization or location names.