CVE-2016-8613

    Dashboard / Vulnerabilities / CVE-2016-8613

    CVE-2016-8613

    Published: 31 Jul 2018Last Modified: 8 Jul 2026

    Summary:

    Details: A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in the web UI does not escape the output causing any HTML or JavaScript to run in the user's browser. The output of the job is stored, making this a stored XSS vulnerability.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 1b42244629952d3444263e9d15993c4c1082ac80
    Fixed -None

    Affected versions

    1.5.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2016-8613 | CVE-DB