REDHAT-BUG-2280187: XSS
A potential XSS issue within Foreman / Katello has been reported. It is possible to inject JavaScript code into the Description field of a User and save it. This code is then executed when opening certain pages (e.g., Host Collections).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2280187?
The severity of REDHAT-BUG-2280187 is considered significant due to the potential for JavaScript injection affecting user security.
How do I fix REDHAT-BUG-2280187?
To fix REDHAT-BUG-2280187, update Foreman and Katello to the latest patched versions provided by the maintainers.
What are the symptoms of REDHAT-BUG-2280187?
The symptoms of REDHAT-BUG-2280187 include unexpected JavaScript execution when viewing affected User descriptions in certain Foreman or Katello pages.
Who is affected by REDHAT-BUG-2280187?
Users of Foreman and Katello are affected by REDHAT-BUG-2280187 if they utilize the Description field for User entries.
What should I do if I cannot patch REDHAT-BUG-2280187 immediately?
If you cannot patch REDHAT-BUG-2280187 immediately, consider restricting access to the affected pages and reviewing user inputs for potential exploits.