Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0089

Опубликовано: 24 мар. 2014
Источник: redhat
CVSS2: 6

Описание

Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

Отчет

Not vulnerable. This issue did not affect the versions of foreman as shipped with Red Hat Enterprise Linux OpenStack Platform 3 or 4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3ruby193-foremanNot affected
Red Hat OpenStack Platform 4foremanNot affected
Red Hat Satellite 6.0foremanFixedRHEA-2014:117510.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1071741Foreman: Stored Cross Site Scripting

6 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

debian
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in app/views/common/500.html. ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

6 Medium

CVSS2