|Summary:||CVE-2017-7535 foreman: XSS in the manage organization page|
|Product:||[Other] Security Response||Reporter:||Andrej Nemec <anemec>|
|Component:||vulnerability||Assignee:||Red Hat Product Security <security-response-team>|
|Status:||NEW ---||QA Contact:|
|Version:||unspecified||CC:||bkearney, cbillett, jmatthew, mmccune, ohadlevy, security-response-team, sisharma, sjagtap, tlestach, tsanders|
|Fixed In Version:||foreman 1.16.0||Doc Type:||If docs needed, set a value|
|Doc Text:||Story Points:||---|
|oVirt Team:||---||RHEL 7.3 requirements from Atomic Host:|
|Cloudforms Team:||---||Target Upstream Version:|
|Bug Depends On:||1469898|
Description Andrej Nemec 2017-06-20 14:21:21 UTC
A cross-site scripting vulnerability was found in foreman in the manage organization page.
Comment 1 Andrej Nemec 2017-06-20 14:21:28 UTC
Acknowledgments: Name: Sanket Jagtap (Red Hat)
Comment 3 Bryan Kearney 2017-08-17 15:40:17 UTC
Do you have a link to an upstream issue? I checked with upstream and they are not aware of this CVE.
Comment 4 Andrej Nemec 2017-08-21 08:20:33 UTC
(In reply to Bryan Kearney from comment #3) > Do you have a link to an upstream issue? I checked with upstream and they > are not aware of this CVE. I assumed that the reported let the upstream know as always. Do you still want me to let them know, or is this resolved for now?
Comment 5 Bryan Kearney 2017-08-21 11:09:16 UTC
Sanket, do you know what the upstream issue is for this bug?
Comment 6 Sanket Jagtap 2017-09-15 05:12:05 UTC
I have not yet tested this with upstream. So, didn't yet report it in upstream, but yes will let them know about this issue.
Comment 7 Andrej Nemec 2017-09-19 08:14:47 UTC
Upstream issue: http://projects.theforeman.org/issues/20963