Bug 1645190 (CVE-2018-16887) - CVE-2018-16887 katello: stored XSS in subscriptions and repositories pages
Summary: CVE-2018-16887 katello: stored XSS in subscriptions and repositories pages
Status: NEW
Alias: CVE-2018-16887
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20181011,repor...
Keywords: Reopened, Security
Depends On: 1662179
Blocks: 1637722
TreeView+ depends on / blocked
 
Reported: 2018-11-01 15:19 UTC by Laura Pardo
Modified: 2019-05-14 12:36 UTC (History)
12 users (show)

(edit)
A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.
Clone Of:
(edit)
Last Closed: 2018-12-26 18:05:52 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:1222 None None None 2019-05-14 12:36 UTC

Description Laura Pardo 2018-11-01 15:19:18 UTC
A flaw was found in katello. An stored XSS in the subscriptions and repositories pages due to an improper sanitization of the new organization input field.


References:
https://projects.theforeman.org/issues/25182

Upstream Patch:
https://github.com/Katello/katello/pull/7757
https://projects.theforeman.org/projects/katello/repository/revisions/17451c950201bedec9bdd3748e17863b550a6be2

Comment 1 Laura Pardo 2018-11-01 15:19:32 UTC
Acknowledgments:

Name: Sanket Jagtap (Red Hat Pune India)

Comment 2 Cedric Buissart 🐶 2018-12-10 16:43:24 UTC
Statement:

Red Hat Subscription Asset Manager does not support the Organization Change, and therefore is not affected by this flaw.

Comment 9 errata-xmlrpc 2019-05-14 12:36:11 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.5 for RHEL 7

Via RHSA-2019:1222 https://access.redhat.com/errata/RHSA-2019:1222


Note You need to log in before you can comment on or make changes to this bug.