Red Hat Bugzilla – Bug 918784
CVE-2013-1823 Katello: Notifications page Username XSS
Last modified: 2016-03-04 07:19:17 EST
Suresh Thiru (sthirugn@redhat.com) of Red Hat reports: Description of problem: In Notifications page, the Username should escape html characters Steps to Reproduce: 1. Create a user named <blink>FOOO</blink> 2. Go to Notifications page and notice that FOOO is in blinking mode in the page Actual results: FOOO is in html blinking mode in the Notifications page Expected results: Username should be displayed fully in Notifications page: <blink>FOOO</blink>
Acknowledgements: This issue was discovered by Sureshkumar Thirugnanasambandan of the Red Hat Quality Engineering Team.
This issue has been addressed in following products: Red Hat Subscription Asset Manager 1.2 Via RHSA-2013:0686 https://rhn.redhat.com/errata/RHSA-2013-0686.html