PT-2018-2570 · Red Hat · Katello+1

Laura Pardo

+1

·

Published

2018-09-11

·

Updated

2022-05-14

·

CVE-2018-16887

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Satellite katello versions prior to 3.9.0
Description A cross-site scripting (XSS) flaw was found in the katello component of Satellite, allowing an attacker with privileges to create or edit organizations and locations to execute XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. The vulnerability is related to insufficient protection of the web page structure.
Recommendations For versions prior to 3.9.0, update to version 3.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Subscriptions and Red Hat Repositories wizards to minimize the risk of exploitation. Avoid using the wizards until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01044
CVE-2018-16887
GHSA-MHHC-R88H-2QRM
RHSA-2019:1222

Affected Products

Satellite
Katello