Actions
Bug #25182
closedCVE-2018-16887 - XSS on Subscription/Repositories pages
Difficulty:
Triaged:
Yes
Bugzilla link:
Pull request:
Description
How to reproduce:
1. Create org with <b> org </b> name
2. Pick Any org on the mast head
3. Go to Subscription page
4, Choose the <b> org </b> organization from the selector
5. Once the page loads, check out the org selector in top left, it's bold
Updated by The Foreman Bot almost 6 years ago
- Status changed from New to Ready For Testing
- Pull request https://github.com/Katello/katello/pull/7757 added
Updated by Amir Fefer almost 6 years ago
- Status changed from Ready For Testing to Closed
Applied in changeset katello|17451c950201bedec9bdd3748e17863b550a6be2.
Updated by Michael Johnson almost 6 years ago
- Target version set to Katello 3.9.0
Updated by Tomer Brisker almost 6 years ago
- Related to Bug #22568: RH repos XUI: page crashes when in Any context added
Updated by Tomer Brisker almost 6 years ago
- Subject changed from XSS on Subscription/Repositories pages to CVE-2018-16887 - XSS on Subscription/Repositories pages
- Found in Releases Katello 3.7.1 added
Actions