Foreman CVE-2014-3653 Cross Site Scripting Vulnerability
BID:70046
Info
Foreman CVE-2014-3653 Cross Site Scripting Vulnerability
| Bugtraq ID: | 70046 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3653 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2014 12:00AM |
| Updated: | Nov 03 2015 07:25PM |
| Credit: | Murray McAllister |
| Vulnerable: |
Redhat Satellite Capsule (for RHEL 7 x86_64) 6.1 Redhat Satellite Capsule (for RHEL 6 x86_64) 6.1 Redhat Satellite (for RHEL 7 x86_64) 6.1 Redhat Satellite (for RHEL 6 x86_64) 6.1 Foreman Foreman 1.6 |
| Not Vulnerable: | |
Discussion
Foreman CVE-2014-3653 Cross Site Scripting Vulnerability
Foreman is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in an unsuspecting user's browser in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Foreman 1.6.0 is vulnerable; other versions may also be affected.
Foreman is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in an unsuspecting user's browser in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Foreman 1.6.0 is vulnerable; other versions may also be affected.
Exploit / POC
Foreman CVE-2014-3653 Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Foreman CVE-2014-3653 Cross Site Scripting Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Foreman CVE-2014-3653 Cross Site Scripting Vulnerability
References:
References: