Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1187466 - (CVE-2014-0141) CVE-2014-0141 Satellite 6: environment name variable XSS
CVE-2014-0141 Satellite 6: environment name variable XSS
Status: CLOSED CURRENTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20150129,repor...
: Security
Depends On:
Blocks: 1187467
  Show dependency treegraph
 
Reported: 2015-01-30 01:10 EST by Kurt Seifried
Modified: 2015-07-04 02:02 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-04 02:02:19 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Kurt Seifried 2015-01-30 01:10:20 EST
Jan Hutař of Red Hat reports:

When I create environment with HTML (like '<script>alert("hello")</script>') 
in name is not escaped properly on some pages when printing it and so might 
mean XSS attack possibility.
Comment 2 Kurt Seifried 2015-07-04 02:02:19 EDT
This was actually fixed prior to GA:

Was reported on: Satellite-6.0.3-RHEL-6-20140313.0
GA release: Satellite-6.0.4-RHEL-6-20140908.0

So this only affected a beta version of Satellite 6. Closing this as CURRENTRELEASE.

Note You need to log in before you can comment on or make changes to this bug.