Red Hat Bugzilla – Bug 1094592
CVE-2014-0183 Katello XSS: HTML in systems name (when registering) gets interpreted on system information page
Last modified: 2016-03-04 07:17:20 EST
Environment names are can contain script tags. See: https://bugzilla.redhat.com/show_bug.cgi?id=1076394
Acknowledgements: This issue was discovered by Jan Hutar of Red Hat.
Statement: This issue affects the versions of katello as shipped with Red Hat Subscription Asset Manager 1.4. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.