Back to bug 1393291

Who When What Removed Added
Andrej Nemec 2016-11-09 09:47:32 UTC Blocks 1391526
Andrej Nemec 2016-11-14 09:17:30 UTC Whiteboard impact=moderate,public=20160512,reported=20161108,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected impact=moderate,public=20160512,reported=20161108,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix
Andrej Nemec 2016-11-14 09:17:38 UTC CC ceph-eng-bugs, sisharma
Kurt Seifried 2016-11-28 18:20:51 UTC Depends On 1399317
Kurt Seifried 2016-11-28 18:21:21 UTC Depends On 1399319
Kurt Seifried 2017-03-15 04:15:06 UTC Blocks 1432306
Kurt Seifried 2017-10-19 20:39:27 UTC Doc Text It was found that foreman is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
Whiteboard impact=moderate,public=20160512,reported=20161108,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix impact=moderate,public=20160512,reported=20161107,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix
Kurt Seifried 2017-10-19 21:20:59 UTC Whiteboard impact=moderate,public=20160512,reported=20161107,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix impact=moderate,public=20160512,reported=20161106,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix
Eric Christensen 2017-10-20 12:55:44 UTC Whiteboard impact=moderate,public=20160512,reported=20161106,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix impact=moderate,public=20160512,reported=20161105,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix
Viliam Križan 2018-02-12 10:33:37 UTC Whiteboard impact=moderate,public=20160512,reported=20161105,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix impact=moderate,public=20160512,reported=20161108,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix
PnT Account Manager 2019-04-22 21:31:26 UTC CC tjay
Product Security DevOps Team 2019-09-29 13:59:56 UTC Whiteboard impact=moderate,public=20160512,reported=20161108,source=redhat,cvss2=4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N,cvss3=6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N,cwe=CWE-79,rhn_satellite_6/foreman=affected,ceph-1.3/foreman=wontfix
Yadnyawalk Tale 2020-08-11 14:04:43 UTC Status NEW CLOSED
Resolution --- ERRATA
Last Closed 2020-08-11 14:04:43 UTC

Back to bug 1393291