CVE-2015-0284
published 2016-04-14CVE-2015-0284: Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web…
PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.24%
65.8th percentile
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Sat5: XSS in uset details
vendor_redhat·2016-02-07·CVSS 5.4
CVE-2016-2144 [MEDIUM] CWE-79 Sat5: XSS in uset details
Sat5: XSS in uset details
[REJECTED CVE] A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users.
Statement: This flaw was found to be a duplicate of CVE-2015-0284. Please see https://access.redhat.com/security/cve/CVE-2015-0284 for information about affected products and security errata.
Package: Security (Red Hat Satellite 5.7) - Affected
Red Hat
Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
vendor_redhat·2015-03-03·CVSS 3.5
CVE-2015-0284 [LOW] CWE-79 Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users.
Package: Server (Red Hat Satellite 5.6) - Will not fix
GHSA
GHSA-q4pf-r4w7-4wpv: Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5
ghsa_unreviewed·2022-05-13·CVSS 3.5
CVE-2015-0284 [LOW] CWE-79 GHSA-q4pf-r4w7-4wpv: Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2144 Sat5: XSS in uset details
bugzilla·2016-03-07·CVSS 5.4
CVE-2016-2144 [MEDIUM] CVE-2016-2144 Sat5: XSS in uset details
CVE-2016-2144 Sat5: XSS in uset details
Jan Hutař of Red Hat reports a XSS vulnerability in the handling of the users first and last name within the Web UI.
External reference:
spacewalk git dd418384171473c3e31386a1b4792f8c555dc744
spacewalk git f3792c79c1c251a49cc4e382be8591636326a794
Discussion:
Acknowledgments:
Name: Jan Hutař (Red Hat)
---
*** This bug has been marked as a duplicate of bug 1181472 ***
---
CVE-2016-2144 was rejected. Reason: Duplicate of CVE-2015-0284
Bugzilla
(CVE-2015-0284) Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
bugzilla·2016-03-04·CVSS 3.5
CVE-2015-0284 [LOW] (CVE-2015-0284) Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
(CVE-2015-0284) Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Jan Hutař reports:
There is stored XSS vulnerability in user details field in Satellite server, they can be exploited by using the REST API to send XML data containing malformed data.
Discussion:
*** This bug has been marked as a duplicate of bug 1181152 ***
Bugzilla
CVE-2015-0284 Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
bugzilla·2015-01-13·CVSS 3.5
CVE-2015-0284 [LOW] CVE-2015-0284 Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
CVE-2015-0284 Red Hat Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Jan Hutař reports:
There is stored XSS vulnerability in user details field in Satellite server, they can be exploited by using the XMLRPC API to send XML data containing malformed data.
Discussion:
*** Bug 1315398 has been marked as a duplicate of this bug. ***
---
External reference:
spacewalk git dd418384171473c3e31386a1b4792f8c555dc744
spacewalk git f3792c79c1c251a49cc4e382be8591636326a794
---
Acknowledgments:
Name: Jan Hutař (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 5.7
Via RHSA-2016:0590 https://rhn.redhat.com/errata/RHSA-2016-0590.html
http://rhn.redhat.com/errata/RHSA-2016-0590.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1181152https://bugzilla.redhat.com/show_bug.cgi?id=1181472https://bugzilla.redhat.com/show_bug.cgi?id=1314906https://bugzilla.redhat.com/show_bug.cgi?id=1315398https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794http://rhn.redhat.com/errata/RHSA-2016-0590.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1181152https://bugzilla.redhat.com/show_bug.cgi?id=1181472https://bugzilla.redhat.com/show_bug.cgi?id=1314906https://bugzilla.redhat.com/show_bug.cgi?id=1315398https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794
2016-04-14
Published