CVE-2023-0119 describes a stored Cross-site Scripting (XSS) vulnerability in Foreman, affecting Red Hat Enterprise Linux and Red Hat Satellite. An authenticated attacker can inject malicious scripts into the Hosts tab's comment section due to insufficient input filtering. This medium-severity vulnerability (CVSS 5.4) allows an attacker to steal user sessions, make unauthorized requests, and obtain credentials. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.13CPE matchmatch criteria | cpe:2.3:a:redhat:satellite:6.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.