Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16887

Опубликовано: 11 окт. 2018
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Versions before 3.9.0 are vulnerable.

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.

Отчет

Red Hat Subscription Asset Manager does not support the Organization Change, and therefore is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Subscription Asset ManagerkatelloNot affected
Red Hat Satellite 6.5 for RHEL 7ansiblerole-insights-clientFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7candlepinFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7createrepo_cFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foremanFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-discovery-imageFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-installerFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-proxyFixedRHSA-2019:122214.05.2019
Red Hat Satellite 6.5 for RHEL 7foreman-selinuxFixedRHSA-2019:122214.05.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1645190katello: stored XSS in subscriptions and repositories pages

EPSS

Процентиль: 48%
0.00252
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 7 лет назад

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Versions before 3.9.0 are vulnerable.

CVSS3: 5.4
github
больше 3 лет назад

katello Cross-site Scripting vulnerability

CVSS3: 5.4
fstec
больше 7 лет назад

Уязвимость системы управления пакетами Katello, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку или межсайтовую подделку запроса

EPSS

Процентиль: 48%
0.00252
Низкий

5.4 Medium

CVSS3