Lucene search

K
redhatRedHatRHSA-2018:0380
HistoryMar 01, 2018 - 12:49 p.m.

(RHSA-2018:0380) Moderate: Red Hat CloudForms security, bug fix, and enhancement update

2018-03-0112:49:56
access.redhat.com
69

0.003 Low

EPSS

Percentile

66.0%

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • A flaw was found in CloudForms in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of this XSS however not all browsers support CSP. (CVE-2017-15125)

This issue was discovered by Yadnyawalk Tale (Red Hat).

Additional Changes:

This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.