CVE-2014-3595

Severity
4.3MEDIUM
EPSS
0.3%
top 46.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22
Latest updateMay 13

Description

Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

NVDredhat/spacewalk-java1.2.39, 1.7.54, 2.0.2+2
NVDredhat/satellite5.4, 5.5, 5.6+2
NVDsuse/manager1.7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xgqv-fw8c-8qm6: Cross-site scripting (XSS) vulnerability in spacewalk-java 12022-05-13
CVEList
CVE-2014-3595: Cross-site scripting (XSS) vulnerability in spacewalk-java 12014-09-22

📋Vendor Advisories

1
Red Hat
Satellite: Spacewalk contains XSS in log file view2014-08-13

💬Community

1
Bugzilla
CVE-2014-3595 Satellite: Spacewalk contains XSS in log file view2014-08-13