Show plain JSON{"acknowledgement": "This issue was discovered by Sureshkumar Thirugnanasambandan (Red Hat Quality Engineering Team).", "affected_release": [{"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "candlepin-0:0.7.24-1.el6_3", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "katello-0:1.2.1.1-1h.el6_4", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "katello-configure-0:1.2.3.1-4h.el6_4", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-actionpack-1:3.0.10-12.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-activemodel-0:3.0.10-3.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-delayed_job-0:2.1.4-3.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-json-0:1.7.3-2.el6_3", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-rack-1:1.3.0-4.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-rails_warden-0:0.5.5-2.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "rubygem-rdoc-0:3.8-6.el6cf", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}, {"advisory": "RHSA-2013:0686", "cpe": "cpe:/a:rhel_sam:1.2::el6", "package": "thumbslug-0:0.0.28.1-1.el6_4", "product_name": "Red Hat Subscription Asset Manager 1.2", "release_date": "2013-03-26T00:00:00Z"}], "bugzilla": {"description": "Katello: Notifications page Username XSS", "id": "918784", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=918784"}, "csaw": false, "cvss": {"cvss_base_score": "4.3", "cvss_scoring_vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "status": "verified"}, "cwe": "CWE-79", "details": ["Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field."], "name": "CVE-2013-1823", "public_date": "2013-03-26T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2013-1823\nhttps://nvd.nist.gov/vuln/detail/CVE-2013-1823"], "threat_severity": "Low"}