First published: Tue Aug 23 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Marcus Schafer Kiwi | <=3.74.1 | |
Novell Suse Studio Onsite | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2650 is classified as a moderate severity cross-site scripting (XSS) vulnerability that can allow unauthorized script execution.
To mitigate CVE-2011-2650, upgrade to Kiwi version 3.74.2 or later and ensure SUSE Studio is updated to version 1.1.4 or later.
CVE-2011-2650 allows remote attackers to inject arbitrary web scripts or HTML, which can lead to unauthorized actions on behalf of users.
CVE-2011-2650 affects users of Kiwi versions prior to 3.74.2 and SUSE Studio version 1.1 prior to 1.1.4.
The vulnerability is present in Kiwi and SUSE Studio Onsite applications up to their specified vulnerable versions.