Medium severity4.8NVD Advisory· Published Jun 5, 2024· Updated Jun 17, 2026
CVE-2024-4812
CVE-2024-4812
Description
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4(expand)+ 1 more
- (no CPE)
- (no CPE)
- cpe:2.3:a:katello_project:katello:-:*:*:*:*:foreman:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2024-4812nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.