Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3653

Опубликовано: 17 сент. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

A cross-site scripting (XSS) flaw was found in Foreman's template preview screen. A remote attacker could use this flaw to perform cross-site scripting attacks by tricking a user into viewing a malicious template. Note that templates are commonly shared among users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack ForemanforemanWill not fix
Red Hat OpenStack Platform 4foremanWill not fix
Red Hat Satellite 6.1aopallianceFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-commons-codec-eap6FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-mime4jFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1atinjectFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1bouncycastleFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1c3p0FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepinFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepin-commonFixedRHSA-2015:159212.08.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1145398foreman: cross-site scripting (XSS) flaw in template preview screen

EPSS

Процентиль: 59%
0.00389
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the template preview funct ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

EPSS

Процентиль: 59%
0.00389
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2014-3653