oss-sec mailing list archives
Foreman 1.2+ stored XSS in fact charts
From: Tomer Brisker <tbrisker () redhat com>
Date: Sun, 5 Nov 2017 17:01:41 +0200
CVE-2017-15100: Facts reported by hosts to Foreman containing HTML are not properly escaped on fact charts in the facts page, statistics page, and trends page when hovering over the chart with the mouse. Affects Foreman 1.2 and higher. Patch available at https://github.com/theforeman/foreman/pull/4967 Fix will be release in Foreman 1.16.0 (to be released). For more information see: http://projects.theforeman.org/issues/21519 -- Have a nice day, Tomer Brisker Red Hat Engineering
Current thread:
- Foreman 1.2+ stored XSS in fact charts Tomer Brisker (Nov 05)
