Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1498976 - (CVE-2017-12175) CVE-2017-12175 Satellite 6: XSS in discovery rule filter autocomplete functionality
CVE-2017-12175 Satellite 6: XSS in discovery rule filter autocomplete functio...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20171005,repor...
: Security
Depends On: 1494515 1498977 1498978
Blocks: 1432305
  Show dependency treegraph
 
Reported: 2017-10-05 13:09 EDT by Kurt Seifried
Modified: 2018-10-16 11:19 EDT (History)
10 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Verified XSS (124.15 KB, image/png)
2018-09-12 14:41 EDT, Lai
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Foreman Issue Tracker 22042 None None None 2017-12-20 11:26 EST
Red Hat Product Errata RHSA-2018:2927 None None None 2018-10-16 11:19 EDT

  None (edit)
Description Kurt Seifried 2017-10-05 13:09:36 EDT
Jan Hutař of Red Hat reports:

There is a XSS possible in discovery rule when you are entering filter and you use autocomplete functionality


Version-Release number of selected component (if applicable):
satellite-6.3.0-18.0.beta.el7sat.noarch
Comment 2 Daniel Lobato Garcia 2017-12-20 11:26:32 EST
Created redmine issue http://projects.theforeman.org/issues/22042 from this bug
Comment 4 Lai 2018-09-12 14:41 EDT
Created attachment 1482812 [details]
Verified XSS
Comment 5 errata-xmlrpc 2018-10-16 11:19:36 EDT
This issue has been addressed in the following products:

  Red Hat Satellite 6.4 for RHEL 7

Via RHSA-2018:2927 https://access.redhat.com/errata/RHSA-2018:2927

Note You need to log in before you can comment on or make changes to this bug.