Jeremy Choi and Keqin Hong of the Red Hat HSS Pen-Test Team reported a stored XSS issue in foreman. Authenticated users who are able to add bookmarks may inject malicious javascript or html that will be executed by other users viewing the page.
Acknowledgements: This issue was discovered by Jeremy Choi and Keqin Hong of the Red Hat HSS Pen-Test Team.
Statement: Not vulnerable. This issue did not affect the versions of foreman as shipped with Red Hat Enterprise Linux OpenStack Platform 3 or 4.