| Vulnerability Name: | CVE-2018-16861 (CCN-154183) | ||||||||||||
| Assigned: | 2018-12-04 | ||||||||||||
| Published: | 2018-12-04 | ||||||||||||
| Updated: | 2019-05-14 | ||||||||||||
| Summary: | A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Foreman before 1.18.3, 1.19.1, and 1.20.0 are vulnerable. | ||||||||||||
| CVSS v3 Severity: | 4.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-79 | ||||||||||||
| Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-16861 Source: REDHAT Type: UNKNOWN RHSA-2019:1222 Source: CCN Type: Red Hat Bugzilla Bug 1645201 (CVE-2018-16861) - CVE-2018-16861 foreman: stored XSS in success notification after entity creation Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16861 Source: XF Type: UNKNOWN redhat-cve201816861-xss(154183) Source: CCN Type: foreman GIT Repository ixes #24807 - unsafe html in toast notification #6041 Source: CCN Type: foreman GIT Repository [CP 1.18] Fixes #24807 - unsafe html in toast notification #6060 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||