CVE-2016-8639
Summary
| CVE | CVE-2016-8639 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-01 13:29:00 UTC |
| Updated | 2023-11-07 02:36:00 UTC |
| Description | It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Satellite | 6.3 | All | All | All |
| Application | Redhat | Satellite | 6.3 | All | All | All |
| Application | Redhat | Satellite Capsule | 6.3 | All | All | All |
| Application | Redhat | Satellite Capsule | 6.3 | All | All | All |
| Application | Theforeman | Foreman | All | All | All | All |
| Application | Theforeman | Foreman | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Foreman CVE-2016-8639 Multiple HTML Injection Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Refactor #15037: Improve editable elements - Foreman | CONFIRM | projects.theforeman.org | Vendor Advisory |
| Fixes #15037 - Improves editable elements in settings by amirfefer · Pull Request #3523 · theforeman/foreman · GitHub | CONFIRM | github.com | Third Party Advisory |
| 1393291 – (CVE-2016-8639) CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.