First published: Tue Mar 27 2018(Updated: )
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/foreman | <1.16.1 | 1.16.1 |
Theforeman Foreman | <1.16.1 | |
Redhat Satellite | =6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1096 is an input sanitization flaw in the id field of the dashboard controller in Foreman before version 1.16.1.
CVE-2018-1096 allows an attacker to perform an SQL injection attack on the back-end database of Foreman before version 1.16.1.
CVE-2018-1096 has a severity rating of 6.5, indicating a medium severity.
To fix CVE-2018-1096, upgrade to Foreman version 1.16.1 or later.
You can find more information about CVE-2018-1096 at the following references: http://projects.theforeman.org/issues/23028, https://github.com/theforeman/foreman/pull/5363, and http://projects.theforeman.org/projects/foreman/repository/revisions/274665e24373de670a9107d4565c10ec41dd5f65