CVE-2017-16012

Impact:
Moderate
Public Date:
2017-03-21
CWE:
CWE-79
Bugzilla:
1591854: CVE-2017-16012 js-jquery: XSS in responses from cross-origin ajax requests

The MITRE CVE dictionary describes this issue as:

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9251. Reason: This candidate is a duplicate of CVE-2015-9251. Notes: All CVE users should reference CVE-2015-9251 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Find out more about CVE-2017-16012 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 6.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Changed
Confidentiality None
Integrity Impact High
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 ruby193-rubygem-jquery-rails Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror50-rubygem-jquery-rails Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror42-rubygem-jquery-rails Under investigation
Red Hat Single Sign-On 7 keycloak Under investigation
Red Hat Satellite 6 tfm-rubygem-jquery-ui-rails Under investigation
Red Hat Satellite 6 ruby193-rubygem-jquery-ui-rails Under investigation
Red Hat OpenStack Platform 9.0 python-XStatic-jQuery Affected
Red Hat OpenStack Platform 8.0 (Liberty) python-XStatic-jQuery Affected
Red Hat OpenStack Platform 13.0 (Queens) python-XStatic-jQuery Affected
Red Hat OpenStack Platform 12.0 python-XStatic-jQuery Affected
Red Hat OpenStack Platform 10 python-XStatic-jQuery Affected
Red Hat JBoss Operations Network 3 cassandra Under investigation
Red Hat JBoss Fuse 7 jquery Affected
Red Hat JBoss EAP 7 console Not affected
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-XStatic-jQuery Will not fix

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.