CVE-2016-3079
published 2016-04-14CVE-2016-3079: Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.58%
72.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spacewalk-java: Multiple XSS issues in WebUI
vendor_redhat·2016-03-29·CVSS 6.1
CVE-2016-3079 [MEDIUM] CWE-79 spacewalk-java: Multiple XSS issues in WebUI
spacewalk-java: Multiple XSS issues in WebUI
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).
Multiple cross-site scripting (XSS) flaws were found in the way certain form data was handled in Red Hat Satellite. A user able to enter form data could use these flaws to perform XSS attacks against other Satellite users.
GHSA
GHSA-rh9g-8vr9-r79f: Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5
ghsa_unreviewed·2022-05-13
CVE-2016-3079 [MEDIUM] CWE-79 GHSA-rh9g-8vr9-r79f: Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3079 spacewalk-java: Multiple XSS issues in WebUI
bugzilla·2016-03-24·CVSS 6.1
CVE-2016-3079 [MEDIUM] CVE-2016-3079 spacewalk-java: Multiple XSS issues in WebUI
CVE-2016-3079 spacewalk-java: Multiple XSS issues in WebUI
Two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it and two XSS issues on pages for entitlements management were reported.
Product bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1320452
https://bugzilla.redhat.com/show_bug.cgi?id=1320444
Discussion:
Acknowledgments:
Name: Jan Hutař (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 5.7
Via RHSA-2016:0590 https://rhn.redhat.com/errata/RHSA-2016-0590.html
Bugzilla
(CVE-2016-3079) XSS on pages for entitlements management
bugzilla·2016-03-23·CVSS 6.1
CVE-2016-3079 [MEDIUM] (CVE-2016-3079) XSS on pages for entitlements management
(CVE-2016-3079) XSS on pages for entitlements management
Description of problem:
There are two XSS issues on pages for entitlements management.
Version-Release number of selected component (if applicable):
spacewalk-java-2.3.8-129.el6sat.noarch
How reproducible:
always
Steps to Reproduce:
1. /rhn/systems/SystemEntitlements.do?">alert(1)
(make sure you have some system registered)
2. /rhn/admin/multiorg/EntitlementDetails.do?label=enterprise_entitled">alert(1)
Actual results:
JavaScript alert gets executed.
Expected results:
Alert should not be executed.
Discussion:
Problem 1) fixed by the AlphaBar fix as part of 1313517
Problem 2) spacewalk.github:
7b9ff9ad
---
spacewalk.github:
982b11c9
---
Since the problem described in this bug report should be
resolved in a recent adv
Bugzilla
(CVE-2016-3079) two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it
bugzilla·2016-03-23·CVSS 6.1
CVE-2016-3079 [MEDIUM] (CVE-2016-3079) two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it
(CVE-2016-3079) two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it
Description of problem:
There are two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it
Version-Release number of selected component (if applicable):
spacewalk-java-2.3.8-129.el6sat.noarch
spacewalk-html-2.3.2-34.el6sat.noarch
How reproducible:
always
Steps to Reproduce:
1/a. Systems -> select ~2 with Provisioning add-on entitlement
-> [Manage] in upper right corner of the page
/b. SSM -> Provisioninng -> Tag Systems -> enter '">alert()'
-> Tag Current Snapshots
/c. SSM -> Systems -> -> Provisioning -> Snapshot Tags
2/a. Systems -> Systems Set Manager
/b. SSM -> in "Groups: Create and manage groups" click "Create"
/c. Fill name: '">alert(1)' and r
http://rhn.redhat.com/errata/RHSA-2016-0590.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1320444https://bugzilla.redhat.com/show_bug.cgi?id=1320452https://bugzilla.redhat.com/show_bug.cgi?id=1320940https://github.com/spacewalkproject/spacewalk/commit/7920542fhttps://github.com/spacewalkproject/spacewalk/commit/7b9ff9adhttps://github.com/spacewalkproject/spacewalk/commit/982b11c9https://github.com/spacewalkproject/spacewalk/commit/b6491ebahttp://rhn.redhat.com/errata/RHSA-2016-0590.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1320444https://bugzilla.redhat.com/show_bug.cgi?id=1320452https://bugzilla.redhat.com/show_bug.cgi?id=1320940https://github.com/spacewalkproject/spacewalk/commit/7920542fhttps://github.com/spacewalkproject/spacewalk/commit/7b9ff9adhttps://github.com/spacewalkproject/spacewalk/commit/982b11c9https://github.com/spacewalkproject/spacewalk/commit/b6491eba
2016-04-14
Published