REDHAT-BUG-1365815: Medium severity foreman vulnerability
Marek Hulán of Red Hat reports:
User can define a job template and specify input name containing JS code. When someone tries to invoke such job, the form is generated based on this name without proper escaping so the JS gets executed.
Upstream issue:
http://projects.theforeman.org/issues/16019
Proposed upstream patch:
https://github.com/theforeman/foreman/pull/3715/commits/4b63d2c7cdad76ed2bf96d9f8dff7e0c5cdabda6
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1365815?
The severity of REDHAT-BUG-1365815 is classified as moderate due to the potential for JavaScript code execution.
How do I fix REDHAT-BUG-1365815?
To fix REDHAT-BUG-1365815, ensure you update to the latest version of Red Hat Foreman that addresses this vulnerability.
What is the impact of REDHAT-BUG-1365815?
The impact of REDHAT-BUG-1365815 is the execution of arbitrary JavaScript code, which could compromise user data or session integrity.
Which versions of Foreman are affected by REDHAT-BUG-1365815?
All versions of Red Hat Foreman prior to the security update related to REDHAT-BUG-1365815 are affected.
Is there a workaround for REDHAT-BUG-1365815?
Currently, there are no known workarounds for REDHAT-BUG-1365815, so it is recommended to apply the available updates.