Lucene search

K
cvelistRedhatCVELIST:CVE-2023-0119
HistorySep 12, 2023 - 3:14 p.m.

CVE-2023-0119 Foreman: stored cross-site scripting in host tab

2023-09-1215:14:29
CWE-79
redhat
www.cve.org
5
cve-2023-0119
foreman
cross-site scripting
hosts tab
user credentials

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

45.0%

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user’s session, make requests on behalf of the user, and obtain user credentials.

CNA Affected

[
  {
    "versions": [
      {
        "status": "unaffected",
        "version": "3.4.2"
      },
      {
        "status": "unaffected",
        "version": "3.5.1.16"
      },
      {
        "status": "unaffected",
        "version": "3.5.2"
      },
      {
        "status": "unaffected",
        "version": "3.6.0"
      }
    ],
    "packageName": "foreman",
    "collectionURL": "https://github.com/theforeman/foreman"
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Satellite 6.13 for RHEL 8",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "foreman",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:3.5.1.17-1.el8sat",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:satellite_capsule:6.13::el8",
      "cpe:/a:redhat:satellite_utils:6.13::el8",
      "cpe:/a:redhat:satellite_maintenance:6.13::el8",
      "cpe:/a:redhat:satellite:6.13::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Satellite 6.13 for RHEL 8",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "foreman",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:3.5.1.17-1.el8sat",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:satellite_capsule:6.13::el8",
      "cpe:/a:redhat:satellite_utils:6.13::el8",
      "cpe:/a:redhat:satellite_maintenance:6.13::el8",
      "cpe:/a:redhat:satellite:6.13::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Satellite 6.14 for RHEL 8",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "foreman",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:3.7.0.9-1.el8sat",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:satellite_maintenance:6.14::el8",
      "cpe:/a:redhat:satellite_utils:6.14::el8",
      "cpe:/a:redhat:satellite:6.14::el8",
      "cpe:/a:redhat:satellite_capsule:6.14::el8"
    ]
  },
  {
    "vendor": "Red Hat",
    "product": "Red Hat Satellite 6.14 for RHEL 8",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "foreman",
    "defaultStatus": "affected",
    "versions": [
      {
        "version": "0:3.7.0.9-1.el8sat",
        "lessThan": "*",
        "versionType": "rpm",
        "status": "unaffected"
      }
    ],
    "cpes": [
      "cpe:/a:redhat:satellite_maintenance:6.14::el8",
      "cpe:/a:redhat:satellite_utils:6.14::el8",
      "cpe:/a:redhat:satellite:6.14::el8",
      "cpe:/a:redhat:satellite_capsule:6.14::el8"
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

45.0%