Project

General

Profile

Bug #21442

Updated by Alexis Mousset almost 2 years ago

With information from nodes: 

 * When running a remote run from the interface the output is not escaped 
 * In node details, the software tab information are not escaped 
 * In all nodes list (Nodes, Groups pages, etc.), the OS column is not escaped 

 (the last too are also visible for pending nodes so it can be trigerred from anyone in the allowed networks. 

 and with lower impact (potential privilege escalation inside Rudder): 

 * tags in rules and directives, rules, when hovering the tag rule in the rules lists (directives and rules pages) 
 * api accounts details when hovering 

Back