VulnerabilityModified
CVE-2016-8639
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name.
MEDIUM 5.4EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- theforeman/foreman · redhat/satellite · redhat/satellite capsule
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/94263Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0336Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639Issue Tracking, Third Party Advisory
- https://github.com/theforeman/foreman/pull/3523Third Party Advisory
- https://projects.theforeman.org/issues/15037Vendor Advisory
- http://www.securityfocus.com/bid/94263Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0336Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639Issue Tracking, Third Party Advisory
- https://github.com/theforeman/foreman/pull/3523Third Party Advisory
- https://projects.theforeman.org/issues/15037Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.