CVE-2014-7811
published 2015-01-15CVE-2014-7811: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.46%
70.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_satellite | <= 5.6 | — |
| redhat | satellite | — | — |
| suse | manager | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
vendor_redhat·2015-03-03·CVSS 3.5
CVE-2015-0284 [LOW] CWE-79 Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users.
Package: Server (Red Hat Satellite 5.6) - Will not fix
Red Hat
Spacewalk: multiple XSS
vendor_redhat·2015-01-12·CVSS 3.5
CVE-2014-7811 [LOW] CWE-79 Spacewalk: multiple XSS
Spacewalk: multiple XSS
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API.
Package: Server (Red Hat Satellite 5.6) - Affected
GHSA
GHSA-mqgf-q94x-fm6r: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5
ghsa_unreviewed·2022-05-17
CVE-2014-7811 [LOW] CWE-79 GHSA-mqgf-q94x-fm6r: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API.
GHSA
GHSA-q4pf-r4w7-4wpv: Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5
ghsa_unreviewed·2022-05-13·CVSS 3.5
CVE-2015-0284 [LOW] CWE-79 GHSA-q4pf-r4w7-4wpv: Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
No detection rules found.
No public exploits indexed.
Bugzilla
(CVE-2015-0284) Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
bugzilla·2016-03-04·CVSS 3.5
CVE-2015-0284 [LOW] (CVE-2015-0284) Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
(CVE-2015-0284) Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Jan Hutař reports:
There is stored XSS vulnerability in user details field in Satellite server, they can be exploited by using the REST API to send XML data containing malformed data.
Discussion:
*** This bug has been marked as a duplicate of bug 1181152 ***
Bugzilla
CVE-2015-0284 Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
bugzilla·2015-01-13·CVSS 3.5
CVE-2015-0284 [LOW] CVE-2015-0284 Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
CVE-2015-0284 Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Jan Hutař reports:
There is stored XSS vulnerability in user details field in Satellite server, they can be exploited by using the XMLRPC API to send XML data containing malformed data.
Discussion:
*** Bug 1315398 has been marked as a duplicate of this bug. ***
---
External reference:
spacewalk git dd418384171473c3e31386a1b4792f8c555dc744
spacewalk git f3792c79c1c251a49cc4e382be8591636326a794
---
Acknowledgments:
Name: Jan Hutař (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 5.7
Via RHSA-2016:0590 https://rhn.redhat.com/errata/RHSA-2016-0590.html
Bugzilla
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
bugzilla·2014-12-11·CVSS 3.5
CVE-2014-7812 [LOW] CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
Mickaël Gallier reports:
There are several stored XSS vulnerabilities in various fields in Satellite
server, they can be exploited by using the REST API to send XML data
containing malformed data.
One of these is in the system-group handling. Please see CVE-014-7811 for
the other vulnerabilities.
Discussion:
Acknowledgement:
Red Hat would like to thank Mickaël Gallier for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
Bugzilla
CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
bugzilla·2014-10-24·CVSS 3.5
CVE-2014-7811 [LOW] CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
Mickaël Gallier reports:
There are several stored XSS vulnerabilities in various fields in Satellite
server, they can be exploited by using the REST API to send XML data
containing malformed data.
Discussion:
Created attachment 951111
SW-master/Sat5-latest patch
This patch applies to the latest Spacewalk and Satellite5 codebase. Sat5.6 patch is still in progress.
---
Created attachment 951859
Sat5.6 patch
This patch applies to the 5.6 branch of the Satellite codebase
---
Acknowledgement:
Red Hat would like to thank Mickaël Gallier for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
---
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0033.htmlhttp://secunia.com/advisories/62183http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0033.htmlhttp://secunia.com/advisories/62183
2015-01-15
Published