{"api_version":"1","generated_at":"2026-07-23T05:38:00+00:00","cve":"CVE-2016-8613","urls":{"html":"https://cve.report/CVE-2016-8613","api":"https://cve.report/api/cve/CVE-2016-8613.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8613","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8613"},"summary":{"title":"CVE-2016-8613","description":"A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in the web UI does not escape the output causing any HTML or JavaScript to run in the user's browser. The output of the job is stored, making this a stored XSS vulnerability.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-07-31 20:29:00","updated_at":"2023-02-12 23:26:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1387232","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1387232","refsource":"MISC","tags":[],"title":"1387232 – (CVE-2016-8613) CVE-2016-8613 foreman: Stored XSS vulnerability in remote execution plugin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:0336","name":"https://access.redhat.com/errata/RHSA-2018:0336","refsource":"MISC","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://projects.theforeman.org/issues/17066/","name":"https://projects.theforeman.org/issues/17066/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Bug #17066: CVE-2016-8613 - XSS in live output - Foreman Remote Execution - Foreman","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/theforeman/foreman_remote_execution/pull/208","name":"https://github.com/theforeman/foreman_remote_execution/pull/208","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Fixes #17066 - escape the life output properly by iNecas · Pull Request #208 · theforeman/foreman_remote_execution · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93859","name":"93859","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Foreman CVE-2016-8613 HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2016-8613","name":"https://access.redhat.com/security/cve/CVE-2016-8613","refsource":"MISC","tags":[],"title":"Red Hat Customer Portal - Access to 24x7 support and knowledge","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8613","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8613","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1387232 – (CVE-2016-8613) CVE-2016-8613 foreman: Stored XSS vulnerability in remote execution plugin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8613","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8613","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8613","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"theforeman","cpe5":"foreman","cpe6":"1.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8613","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"theforeman","cpe5":"foreman","cpe6":"1.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2016-8613","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in the web UI does not escape the output causing any HTML or JavaScript to run in the user's browser. The output of the job is stored, making this a stored XSS vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79","cweId":"CWE-79"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"The Foreman Project","product":{"product_data":[{"product_name":"foreman","version":{"version_data":[{"version_affected":"=","version_value":"1.5.1"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.securityfocus.com/bid/93859","refsource":"MISC","name":"http://www.securityfocus.com/bid/93859"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8613","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8613"},{"url":"https://github.com/theforeman/foreman_remote_execution/pull/208","refsource":"MISC","name":"https://github.com/theforeman/foreman_remote_execution/pull/208"},{"url":"https://projects.theforeman.org/issues/17066/","refsource":"MISC","name":"https://projects.theforeman.org/issues/17066/"}]},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.0"}]}},"nvd":{"publishedDate":"2018-07-31 20:29:00","lastModifiedDate":"2023-02-12 23:26:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:theforeman:foreman:1.5.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8613","Ordinal":"95268","Title":"CVE-2016-8613","CVE":"CVE-2016-8613","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8613","Ordinal":"1","NoteData":"A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in the web UI does not escape the output causing any HTML or JavaScript to run in the user's browser. The output of the job is stored, making this a stored XSS vulnerability.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8613","Ordinal":"2","NoteData":"2018-07-31","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8613","Ordinal":"3","NoteData":"2018-08-01","Type":"Other","Title":"Modified"}]}}}