First published: Mon May 13 2024(Updated: )
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Katello Project Katello Foreman | ||
Redhat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.