Red Hat Satellite vulnerabilities
2 known vulnerabilities affecting red_hat/red_hat_satellite.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2017-7513P4MEDIUMCVSS 5.4v52018-08-22
CVE-2017-7513 [MEDIUM] CWE-295 CVE-2017-7513: It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
nvd
CVE-2017-7514P4MEDIUMCVSS 5.4v5.8.02018-07-30
CVE-2017-7514 [MEDIUM] CWE-79 CVE-2017-7514: A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat S
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.
nvd