Описание
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.
Отчет
This issue was fixed in current releases of foreman on Satellite 6.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenStack Foreman | foreman | Not affected | ||
| Red Hat OpenStack Platform 3 | ruby193-foreman | Will not fix | ||
| Red Hat OpenStack Platform 4 | foreman | Will not fix | ||
| Red Hat Satellite 6.0 | foreman | Fixed | RHEA-2014:1175 | 10.09.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before ...
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.
EPSS
4.3 Medium
CVSS2