CVE-2018-16861Cross-site Scripting in Foreman

Severity
4.8MEDIUMNVD
CNA7.6
EPSS
0.4%
top 40.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateMay 14

Description

A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Foreman before 1.18.3, 1.19.1, and 1.20.0 are vulnerable.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

NVDtheforeman/foreman1.19.01.19.1+2
CVEListV5the_foreman_project/foreman1.18.3, 1.19.1, 1.20.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w3p6-8cgj-c9xc: A cross-site scripting (XSS) flaw was found in the foreman component of satellite2022-05-14
CVEList
CVE-2018-16861: A cross-site scripting (XSS) flaw was found in the foreman component of satellite2018-12-07

📋Vendor Advisories

1
Red Hat
foreman: stored XSS in success notification after entity creation2018-09-04

💬Community

1
Bugzilla
CVE-2018-16861 foreman: stored XSS in success notification after entity creation2018-11-01
CVE-2018-16861 — Cross-site Scripting in Foreman | cvebase