CVE-2018-16887
Dashboard / Vulnerabilities / CVE-2018-16887
Summary:
Details: A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Versions before 3.9.0 are vulnerable.
References: https://access.redhat.com/errata/RHSA-2019:1222, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16887
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
3.9.0.rc2
3.9.0.rc1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
