First published: Tue Jun 12 2018(Updated: )
A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting in CloudForms 5.9.3.1 build due to improper sanitization of user input in Name field.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat CloudForms Management Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1590538 is classified as medium due to the stored cross-site scripting vulnerability.
To fix REDHAT-BUG-1590538, ensure that the user input in the Name field is properly sanitized and updated to the latest patched version of CloudForms.
CloudForms version 5.9.3.1 is specifically affected by REDHAT-BUG-1590538.
REDHAT-BUG-1590538 is a stored cross-site scripting (XSS) vulnerability.
Yes, user input validation is crucial to prevent vulnerabilities like the one described in REDHAT-BUG-1590538.