CVE-2011-1594
published 2014-02-05CVE-2011-1594: A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.47%
70.8th percentile
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spacewalk | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v4fr-cg8r-vwm7: Open redirect vulnerability in Spacewalk 1
ghsa_unreviewed·2022-05-17
CVE-2011-1594 [MEDIUM] CWE-20 GHSA-v4fr-cg8r-vwm7: Open redirect vulnerability in Spacewalk 1
Open redirect vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url_bounce parameter.
Red Hat
CVE-2011-1594: A flaw was found in Spacewalk, as used in Red Hat Network Satellite
vendor_redhat·2014-02-05·CVSS 6.5
CVE-2011-1594 [MEDIUM] CWE-601 CVE-2011-1594: A flaw was found in Spacewalk, as used in Red Hat Network Satellite
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
Mitigation: Mitigation for this issue is either not available or the currently available opt
No detection rules found.
No public exploits indexed.
http://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://access.redhat.com/security/cve/CVE-2011-1594https://bugzilla.redhat.com/show_bug.cgi?id=672167https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=672167https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html
2014-02-05
Published