CVE-2011-0717
published 2011-02-25CVE-2011-0717: Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to…
PriorityP428medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.02%
78.7th percentile
Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_satellite_server | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3wjv-m5rx-86vp: Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5
ghsa_unreviewed·2022-05-17
CVE-2011-0717 [MEDIUM] GHSA-3wjv-m5rx-86vp: Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5
Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.
Red Hat
Spacewalk: Session fixation flaw
vendor_redhat·2011-02-23·CVSS 5.8
CVE-2011-0717 [MEDIUM] CWE-384 Spacewalk: Session fixation flaw
Spacewalk: Session fixation flaw
Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0717 CVE-2011-0718 spacewalk-backend various flaws [fedora-all]
bugzilla·2011-02-23·CVSS 5.8
CVE-2011-0717 [MEDIUM] CVE-2011-0717 CVE-2011-0718 spacewalk-backend various flaws [fedora-all]
CVE-2011-0717 CVE-2011-0718 spacewalk-backend various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=672159
Please note: this issue affects multiple s
Bugzilla
CVE-2011-0717 Satellite, Spacewalk: Session fixation flaw
bugzilla·2011-01-24·CVSS 5.8
CVE-2011-0717 [MEDIUM] CVE-2011-0717 Satellite, Spacewalk: Session fixation flaw
CVE-2011-0717 Satellite, Spacewalk: Session fixation flaw
A session fixation flaw was found in the way Red Hat
Network (RHN) Satellite and Spacewalk services handled
session cookies. An RHN Satellite or Spacewalk Server
user able to pre-set the session cookie in a victim's
browser to a valid value could use this flaw to hijack
the victim's session after the next log in.
References:
[1] http://en.wikipedia.org/wiki/Session_fixation
[2] http://shiflett.org/articles/session-fixation
Acknowledgements:
Red Hat would like to thank Thomas Biege of the SuSE Security Team
for reporting this issue.
Discussion:
The CVE identifier of CVE-2011-0717 has been assigned to this issue.
---
This issue has been addressed in following products:
Red Hat Network Satellite Server v 5.4
Via RHSA-2011:030
http://secunia.com/advisories/43487http://www.redhat.com/support/errata/RHSA-2011-0300.htmlhttp://www.securityfocus.com/bid/46528http://www.securitytracker.com/id?1025116http://www.vupen.com/english/advisories/2011/0491https://bugzilla.redhat.com/show_bug.cgi?id=672159https://exchange.xforce.ibmcloud.com/vulnerabilities/65658http://secunia.com/advisories/43487http://www.redhat.com/support/errata/RHSA-2011-0300.htmlhttp://www.securityfocus.com/bid/46528http://www.securitytracker.com/id?1025116http://www.vupen.com/english/advisories/2011/0491https://bugzilla.redhat.com/show_bug.cgi?id=672159https://exchange.xforce.ibmcloud.com/vulnerabilities/65658
2011-02-25
Published