CVE-2023-0119
published 2023-09-12CVE-2023-0119: A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.56%
42.5th percentile
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Foreman: Stored cross-site scripting in host tab
vendor_redhat·2023-03-12·CVSS 5.4
CVE-2023-0119 [MEDIUM] CWE-79 Foreman: Stored cross-site scripting in host tab
Foreman: Stored cross-site scripting in host tab
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
Statement: This issue does not affect Satellite versions 6.12 and below.
GHSA
GHSA-6fr9-c775-x826: A stored Cross-site scripting vulnerability was found in foreman
ghsa_unreviewed·2023-09-12
CVE-2023-0119 [MEDIUM] CWE-79 GHSA-6fr9-c775-x826: A stored Cross-site scripting vulnerability was found in foreman
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:3387https://access.redhat.com/errata/RHSA-2023:6818https://access.redhat.com/security/cve/CVE-2023-0119https://bugzilla.redhat.com/show_bug.cgi?id=2159104https://projects.theforeman.org/issues/35977https://access.redhat.com/errata/RHSA-2023:3387https://access.redhat.com/errata/RHSA-2023:6818https://access.redhat.com/security/cve/CVE-2023-0119https://bugzilla.redhat.com/show_bug.cgi?id=2159104https://projects.theforeman.org/issues/35977
2023-09-12
Published