Project

General

Profile

Actions

Bug #23028

closed

CVE-2018-1096: SQL injection in dashboard controller

Added by Tomer Brisker over 6 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
High
Assignee:
Category:
Security
Target version:
Fixed in Releases:
Found in Releases:

Description

Widget id is not properly escaped for save_positions action on the dashboard, leading to SQL injection possibility.
This only allows injecting conditions to the select conditions, as it is a prepared query it does not allow executing additional commands.
It is only available to authenticated users.

This issue was reported by Martin Povolný from Red Hat.


Related issues 1 (0 open1 closed)

Related to Foreman - Refactor #8106: Save dashboard widgets in DB to increase flexibilityClosedTomer Brisker10/26/2014Actions
Actions

Also available in: Atom PDF