Project

General

Profile

Actions

Bug #16024

closed

Foreman form helpers do not escape JS when rendering label

Added by Marek Hulán over 7 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

The issue was introduced in Foreman 1.6. There's only one dynamic :label => in Foreman that uses MailNotification name which we don't allow users to modify so there's no vulnerable code in Foreman. But remote execution plugin that rely on this label to be escaped. Setting to 1.12.2, feel free to reset. For REX this is pretty important though.


Related issues 1 (0 open1 closed)

Related to Foreman Remote Execution - Bug #16019: CVE-2016-6319 - Persistent XSS in job invocation form triggered by unescaped user input nameResolvedMarek Hulán08/09/2016Actions
Actions #1

Updated by The Foreman Bot over 7 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/3715 added
Actions #2

Updated by Marek Hulán over 7 years ago

  • Category changed from Web Interface to Security
Actions #3

Updated by Marek Hulán over 7 years ago

  • Related to Bug #16019: CVE-2016-6319 - Persistent XSS in job invocation form triggered by unescaped user input name added
Actions #4

Updated by Marek Hulán over 7 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF