Bug #25182
closed
CVE-2018-16887 - XSS on Subscription/Repositories pages
Added by Amir Fefer about 6 years ago.
Updated almost 6 years ago.
Description
How to reproduce:
1. Create org with <b> org </b> name
2. Pick Any org on the mast head
3. Go to Subscription page
4, Choose the <b> org </b> organization from the selector
5. Once the page loads, check out the org selector in top left, it's bold
- Status changed from New to Ready For Testing
- Pull request https://github.com/Katello/katello/pull/7757 added
- Status changed from Ready For Testing to Closed
- Target version set to Katello 3.9.0
- Triaged changed from No to Yes
- Bugzilla link set to 1662179
- Related to Bug #22568: RH repos XUI: page crashes when in Any context added
- Subject changed from XSS on Subscription/Repositories pages to CVE-2018-16887 - XSS on Subscription/Repositories pages
- Found in Releases Katello 3.7.1 added
Also available in: Atom
PDF