VDB
EN
MEDIUM 5.4

GHSA-mhhc-r88h-2qrm

katello Cross-site Scripting vulnerability

상세

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Versions before 3.9.0 are vulnerable.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

RubyGems / katello
최초 영향 버전: 0 수정 버전: 3.9.0
수정 bundle update katello

참고