A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14664 | issue tracking third party advisory |
https://projects.theforeman.org/issues/25169 | issue tracking third party advisory |
http://www.securityfocus.com/bid/106553 | vdb entry third party advisory |
https://access.redhat.com/errata/RHSA-2019:1222 | vendor advisory |