First published: Thu Jul 26 2018(Updated: )
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Foreman | <1.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7535 is a vulnerability in Foreman before version 1.16.0 that allows for stored XSS in organizations/locations assignment to hosts.
CVE-2017-7535 has a severity rating of 6.1 (Medium).
Exploiting CVE-2017-7535 requires a user to actively assign hosts to an organization that contains HTML in its name visible to the user prior to taking action.
Foreman before version 1.16.0 is affected by CVE-2017-7535.
Upgrading to Foreman version 1.16.0 or later fixes CVE-2017-7535.