PT-2018-2570 · Red Hat · Katello+1
Laura Pardo
+1
·
Published
2018-09-11
·
Updated
2022-05-14
·
CVE-2018-16887
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Satellite katello versions prior to 3.9.0
Description
A cross-site scripting (XSS) flaw was found in the katello component of Satellite, allowing an attacker with privileges to create or edit organizations and locations to execute XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. The vulnerability is related to insufficient protection of the web page structure.
Recommendations
For versions prior to 3.9.0, update to version 3.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Subscriptions and Red Hat Repositories wizards to minimize the risk of exploitation. Avoid using the wizards until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Satellite
Katello