Executive brief
A security vulnerability exists in the Migration Planner user interface, a tool used to assist in infrastructure migrations. An attacker can register a malicious discovery agent that includes a specially crafted link; if a legitimate user clicks this link, malicious code executes in their browser. This could allow an attacker to hijack the user's session, potentially leading to unauthorized access to sensitive organizational data and the ability to perform actions on the user's behalf.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in migration-planner-ui-app due to improper validation of the 'credentialUrl' field reported by discovery agents. The application renders this URL using react-router-dom's Link component and standard anchor tags without verifying the URI scheme. An attacker with low privileges can register a malicious agent with a 'javascript:' URI. When an administrative user interacts with the link in the AgentStatusView or Environment views, the payload executes within the context of the console.redhat.com origin. This allows for the theft of Red Hat SSO session tokens, enabling cross-tenant API actions. The issue was addressed by implementing a URL validation helper that restricts links to http and https protocols.
Affected products
- Red Hat migration-planner-ui-app unspecified
Timeline
- 2026-06-02: other: Fix pull request submitted to GitHub repository
- 2026-06-03: patched: Fix merged into master branch
- 2026-06-09: disclosed: Bug reported to Red Hat Bugzilla
- 2026-06-10: advisory: CVE published to NVD and Red Hat security portal