First published: Mon Jul 30 2018(Updated: )
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Network Satellite Server | <5.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7514 has a medium severity rating due to the potential for XSS attacks affecting users.
To fix CVE-2017-7514, upgrade to Red Hat Satellite version 5.8.0 or later.
The impact of CVE-2017-7514 allows unauthorized users to execute malicious scripts in the context of another user's session.
Users of Red Hat Satellite versions prior to 5.8.0 are affected by CVE-2017-7514.
Yes, CVE-2017-7514 can be exploited remotely if an attacker can induce a victim to click on a crafted link.