Project

General

Profile

Bug #25182

CVE-2018-16887 - XSS on Subscription/Repositories pages

Added by Amir Fefer over 1 year ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
Yes
Bugzilla link:
Fixed in Releases:
Found in Releases:

Description

How to reproduce:
1. Create org with <b> org </b> name
2. Pick Any org on the mast head
3. Go to Subscription page
4, Choose the <b> org </b> organization from the selector
5. Once the page loads, check out the org selector in top left, it's bold


Related issues

Related to Katello - Bug #22568: RH repos XUI: page crashes when in Any contextClosed

Associated revisions

Revision 17451c95 (diff)
Added by Amir Fefer over 1 year ago

Fixes #25182 - fix xss on react pages

History

#1 Updated by The Foreman Bot over 1 year ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/Katello/katello/pull/7757 added

#2 Updated by Amir Fefer over 1 year ago

  • Status changed from Ready For Testing to Closed

#3 Updated by Michael Johnson over 1 year ago

  • Target version set to Katello 3.9.0

#4 Updated by Michael Johnson over 1 year ago

  • Triaged changed from No to Yes

#5 Updated by Tomer Brisker over 1 year ago

  • Bugzilla link set to 1662179

#6 Updated by Tomer Brisker over 1 year ago

  • Related to Bug #22568: RH repos XUI: page crashes when in Any context added

#7 Updated by Tomer Brisker over 1 year ago

  • Subject changed from XSS on Subscription/Repositories pages to CVE-2018-16887 - XSS on Subscription/Repositories pages
  • Found in Releases Katello 3.7.1 added

Also available in: Atom PDF