CVE-2014-3531Cross-site Scripting in Foreman

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 48.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 18
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fvgq-9cr6-84mj: Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 12022-05-17
CVEList
CVE-2014-3531: Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 12017-10-18

📋Vendor Advisories

1
Red Hat
foreman: XSS with operating system name/description2014-07-11

💬Community

1
Bugzilla
CVE-2014-3531 foreman: XSS with operating system name/description2014-06-12
CVE-2014-3531 — Cross-site Scripting in Foreman | cvebase