Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAE=eJscBcsPYzh61Cz8Pp-b9T_wiDbHykG=NCUvD8sQ8+vdFrA@mail.gmail.com>
Date: Sun, 5 Nov 2017 17:01:41 +0200
From: Tomer Brisker <tbrisker@...hat.com>
To: oss-security@...ts.openwall.com
Cc: foreman-security@...glegroups.com
Subject: Foreman 1.2+ stored XSS in fact charts

CVE-2017-15100: Facts reported by hosts to Foreman containing HTML are
not properly escaped on fact charts in the facts page, statistics
page, and trends page when hovering over the chart with the mouse.

Affects Foreman 1.2 and higher.

Patch available at https://github.com/theforeman/foreman/pull/4967
Fix will be release in Foreman 1.16.0 (to be released).
For more information see: http://projects.theforeman.org/issues/21519

-- 
Have a nice day,
Tomer Brisker
Red Hat Engineering

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.