CVE-2017-15100

Impact:
Moderate
Public Date:
2017-10-31
CWE:
CWE-79
Bugzilla:
1508551: CVE-2017-15100 foreman: Stored XSS in fact name or value

The MITRE CVE dictionary describes this issue as:

An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.

Find out more about CVE-2017-15100 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue affects the versions of foreman as shipped with Red Hat Satellite version 6 and Ceph Storage version 1.3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

CVSS v3 metrics

CVSS3 Base Score 6.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Satellite 6.4 for RHEL 7 (foreman) RHSA-2018:2927 2018-10-16
Red Hat Satellite 6.4 for RHEL 7 (foreman) RHSA-2018:2927 2018-10-16

Affected Packages State

Platform Package State
Red Hat Satellite 6 foreman Fix deferred
Red Hat Ceph Storage 1.3 foreman Will not fix

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.