Описание
A flaw was found in migration-planner. Insufficient validation of the AgentStatusUpdate.CredentialUrl field allows an authenticated attacker to store a malicious javascript: URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information.
Дополнительная информация
Статус:
Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2487073migration-planner: credentialUrl Validator Accepts javascript: URLs
6.3 Medium
CVSS3
6.3 Medium
CVSS3