Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1125181 - HTML tags should be escaped when we update any parameter value under settings tab
HTML tags should be escaped when we update any parameter value under settings...
Status: CLOSED ERRATA
Product: Red Hat Satellite 6
Classification: Red Hat
Component: Settings (Show other bugs)
6.0.4
Unspecified Unspecified
unspecified Severity medium (vote)
: GA
: Unused
Assigned To: Ohad Levy
Corey Welton
http://projects.theforeman.org/issues...
: Triaged
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-07-31 05:15 EDT by Sachin Ghai
Modified: 2016-07-27 04:43 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-07-27 04:43:17 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
HTML tags properly escaped when updating parameter under settings tab. (84.91 KB, image/png)
2016-05-29 09:21 EDT, Gail Steiger
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Foreman Issue Tracker 6858 None None None 2016-04-22 11:35 EDT
Red Hat Product Errata RHBA-2016:1500 normal SHIPPED_LIVE Red Hat Satellite 6.2 Base Libraries 2016-07-27 08:24:38 EDT

  None (edit)
Comment 1 Dominic Cleal 2014-07-31 05:27:10 EDT
I don't think this has any security implications, but in future, please treat HTML escaping issues as having a potential security (XSS) impact and allow us to evaluate them first.

Ideal procedure is to mark the bug as private for the security team and for Foreman issues, e-mail foreman-security@googlegroups.com (http://theforeman.org/security.html).  We'll check it out and then handle appropriately.  Thanks.
Comment 2 Dominic Cleal 2014-07-31 05:28:14 EDT
Created redmine issue http://projects.theforeman.org/issues/6858 from this bug
Comment 5 Bryan Kearney 2015-08-25 13:59:42 EDT
Upstream bug component is Provisioning
Comment 6 Bryan Kearney 2015-09-02 13:23:06 EDT
Upstream bug component is Settings
Comment 7 Bryan Kearney 2016-03-06 04:10:19 EST
Moving to POST since upstream bug http://projects.theforeman.org/issues/6858 has been closed
-------------
Amir Fefer
Applied in changeset commit:e108822a1a3ab567ea17d733754ccc9c9447dc8a.
Comment 10 Gail Steiger 2016-05-29 09:21 EDT
Created attachment 1162621 [details]
HTML tags properly escaped when updating parameter under settings tab.
Comment 12 errata-xmlrpc 2016-07-27 04:43:17 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2016:1500

Note You need to log in before you can comment on or make changes to this bug.