CVE-2011-2919
published 2014-02-05CVE-2011-2919: Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.19%
64.4th percentile
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spacewalk | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spacewalk: XSS on SystemGroupList.do page
vendor_redhat·2011-09-15·CVSS 4.3
CVE-2011-2919 [MEDIUM] CWE-79 Spacewalk: XSS on SystemGroupList.do page
Spacewalk: XSS on SystemGroupList.do page
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page.
GHSA
GHSA-7vjr-395v-c89g: Cross-site scripting (XSS) vulnerability in Spacewalk 1
ghsa_unreviewed·2022-05-17
CVE-2011-2919 [MEDIUM] CWE-79 GHSA-7vjr-395v-c89g: Cross-site scripting (XSS) vulnerability in Spacewalk 1
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2919 RHN Satellite / Spacewalk: XSS on SystemGroupList.do page [fedora-all]
bugzilla·2011-09-15·CVSS 4.3
CVE-2011-2919 [MEDIUM] CVE-2011-2919 RHN Satellite / Spacewalk: XSS on SystemGroupList.do page [fedora-all]
CVE-2011-2919 RHN Satellite / Spacewalk: XSS on SystemGroupList.do page [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=713478
Please note: this issue affect
Bugzilla
CVE-2011-2919 RHN Satellite / Spacewalk: XSS on SystemGroupList.do page
bugzilla·2011-06-15·CVSS 4.3
CVE-2011-2919 [MEDIUM] CVE-2011-2919 RHN Satellite / Spacewalk: XSS on SystemGroupList.do page
CVE-2011-2919 RHN Satellite / Spacewalk: XSS on SystemGroupList.do page
It was found that application for listing of system groups in Red Hat Network
Satellite Server and Spacewalk services did not properly HTML escape
the content of QueryString. A remote attacker could use this flaw to conduct
XSS attacks, potentially leading into attacker's ability to steal
the users' session cookie.
Acknowledgements:
Red Hat would like to thank Daniel Karanja Muturi for reporting this issue.
Discussion:
This issue has been addressed in following products:
Red Hat Network Satellite Server v 5.4
Via RHSA-2011:1299 https://rhn.redhat.com/errata/RHSA-2011-1299.html
---
Created spacewalk-backend tracking bugs for this issue
Affects: fedora-all [bug 738818]
---
(In reply to comment #12)
> Created
http://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=713478https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1299.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=713478https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html
2014-02-05
Published