First published: Mon May 13 2024(Updated: )
A potential XSS issue within Foreman / Katello has been reported. It is possible to inject JavaScript code into the Description field of a User and save it. This code is then executed when opening certain pages (e.g., Host Collections).
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman | ||
Katello Katello |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2280187 is considered significant due to the potential for JavaScript injection affecting user security.
To fix REDHAT-BUG-2280187, update Foreman and Katello to the latest patched versions provided by the maintainers.
The symptoms of REDHAT-BUG-2280187 include unexpected JavaScript execution when viewing affected User descriptions in certain Foreman or Katello pages.
Users of Foreman and Katello are affected by REDHAT-BUG-2280187 if they utilize the Description field for User entries.
If you cannot patch REDHAT-BUG-2280187 immediately, consider restricting access to the affected pages and reviewing user inputs for potential exploits.