Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1096

Опубликовано: 28 мар. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

An input sanitization flaw was found in the id field of the dashboard controller. A user could use this flaw to perform a SQL injection attack on the back-end database.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3foremanNot affected
Red Hat Satellite 6.4 for RHEL 7ansiblerole-insights-clientFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7candlepinFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7createrepo_cFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foremanFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foreman-installerFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foreman-proxyFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foreman-selinuxFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7goferFixedRHSA-2018:292716.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=1561061foreman: SQL injection due to improper handling of the widget id parameter

EPSS

Процентиль: 54%
0.00315
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 8 лет назад

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

CVSS3: 6.5
debian
почти 8 лет назад

An input sanitization flaw was found in the id field in the dashboard ...

CVSS3: 6.5
github
больше 3 лет назад

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

EPSS

Процентиль: 54%
0.00315
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2018-1096