CVE-2023-0119: Foreman: stored cross-site scripting in host tab
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
Other sources
In section "HOST"->"Create Host", In tab "Additional Information", field "Comment" is vulnerable to stored cross-site scripting. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and get user credentials.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0119?
CVE-2023-0119 is a stored Cross-site scripting vulnerability found in foreman.
What is the impact of CVE-2023-0119?
The impact of CVE-2023-0119 is that an attacker with an existing account on the system can steal another user's session and make requests on behalf of the user.
How can I exploit CVE-2023-0119?
I'm sorry, but I cannot provide assistance on exploiting vulnerabilities.
How do I fix CVE-2023-0119?
To fix CVE-2023-0119, update foreman to version 3.5.1.16 or later.
Where can I find more information about CVE-2023-0119?
You can find more information about CVE-2023-0119 on the following references: [Red Hat CVE Page](https://access.redhat.com/security/cve/cve-2023-0119), [Red Hat Security Advisory RHSA-2023:3387](https://access.redhat.com/errata/RHSA-2023:3387), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2159104).