First published: Tue Jun 12 2018(Updated: )
A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting in CloudForms 5.9.3.1 build due to improper sanitization of user input in Name field.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible-tower | <0:3.5.2-1.el7a | 0:3.5.2-1.el7a |
redhat/cfme | <0:5.10.9.1-1.el7cf | 0:5.10.9.1-1.el7cf |
redhat/cfme-amazon-smartstate | <0:5.10.9.1-1.el7cf | 0:5.10.9.1-1.el7cf |
redhat/cfme-appliance | <0:5.10.9.1-1.el7cf | 0:5.10.9.1-1.el7cf |
redhat/cfme-gemset | <0:5.10.9.1-1.el7cf | 0:5.10.9.1-1.el7cf |
redhat/ovirt-ansible-hosted-engine-setup | <0:1.0.23-1.el7e | 0:1.0.23-1.el7e |
redhat/ovirt-ansible-roles | <0:1.1.7-1.el7e | 0:1.1.7-1.el7e |
redhat/ovirt-ansible-vm-infra | <0:1.1.19-1.el7e | 0:1.1.19-1.el7e |
redhat/v2v-conversion-host | <0:1.14.2-1.el7e | 0:1.14.2-1.el7e |
Redhat Cloudforms Management Engine | =4.7 | |
Redhat Cloudforms Management Engine | =5.8 | |
Redhat Cloudforms Management Engine | =5.9 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10854 is a vulnerability in cloudforms version 5.8 and 5.9 that allows for cross-site scripting attacks.
CVE-2018-10854 affects cloudforms version 5.8 and 5.9 by enabling stored cross-site scripting due to improper sanitization of user input in the Name field.
The severity of CVE-2018-10854 is medium with a CVSS score of 6.5.
To fix CVE-2018-10854, upgrade to a version of cloudforms that is not affected by the vulnerability.
You can find more information about CVE-2018-10854 on the Red Hat errata page and CVE details page.