CVE-2024-4812 describes a stored cross-site scripting (XSS) vulnerability within the Katello plugin for Foreman, affecting Katello and Red Hat Satellite products. An authenticated, high-privileged attacker can inject malicious JavaScript into a user's "Description" field, which executes when other users view specific pages like Host Collections. The vulnerability has a medium CVSS score of 4.8, indicating low impact on confidentiality and integrity, and requires user interaction. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:katello_project:katello:-:*:*:*:*:foreman:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.