CVE-2020-1693XML External Entity (XXE) Injection in Redhat Spacewalk

Severity
9.8CRITICALNVD
CNA8.6
EPSS
7.2%
top 8.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateMay 24

Description

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDredhat/spacewalk< 2.9
CVEListV5red_hat/spacewalkAll spacewalk versions up 2.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-79v3-cg9r-f55q: A flaw was found in Spacewalk up to version 22022-05-24
CVEList
CVE-2020-1693: A flaw was found in Spacewalk up to version 22020-02-17

📋Vendor Advisories

1
Red Hat
spacewalk: XML entity attacks on /rpc/api2020-02-11

💬Community

1
Bugzilla
CVE-2020-1693 spacewalk: XML entity attacks on /rpc/api2020-01-13
CVE-2020-1693 — XML External Entity (XXE) Injection | cvebase