CVE-2024-4812

A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:katello_project:katello:-:*:*:*:*:foreman:*:*
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-4812 - Third Party Advisory () https://access.redhat.com/security/cve/CVE-2024-4812 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2280187 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2280187 - Issue Tracking, Third Party Advisory

18 Jun 2024, 18:49

Type Values Removed Values Added
CPE cpe:2.3:a:katello_project:katello:-:*:*:*:*:foreman:*:*
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2024-4812 - () https://access.redhat.com/security/cve/CVE-2024-4812 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2280187 - () https://bugzilla.redhat.com/show_bug.cgi?id=2280187 - Issue Tracking, Third Party Advisory
First Time Katello Project katello
Redhat satellite
Redhat
Katello Project

06 Jun 2024, 14:17

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en el complemento Katello para Foreman, donde es posible almacenar código JavaScript malicioso en el campo "Descripción" de un usuario. Este código se puede ejecutar al abrir determinadas páginas, por ejemplo, Colecciones de hosts.

05 Jun 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-05 15:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4812

Mitre link : CVE-2024-4812

CVE.ORG link : CVE-2024-4812


JSON object : View

Products Affected

redhat

  • satellite

katello_project

  • katello
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')