Date: Mon, 25 Sep 2017 13:36:48 +0200 From: Marek Hulán <mhulan@...hat.com> To: oss-security@...ts.openwall.com Cc: foreman-security@...glegroups.com Subject: Foreman 1.1+ stored XSS in organizations/locations assignment to hosts CVE-2017-7535: Attempting to assign all hosts to an organization or location that contains HTML does not properly escape the html in the toast notification informing of success. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action. Affects Foreman 1.1 and higher. Patch available at https://github.com/theforeman/foreman/pull/4851 Fix will be released in Foreman 1.16.0 (to be released) For more information please see the Redmine issue http:// projects.theforeman.org/issues/20963 -- Marek
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ