CVE-2011-2919: XSS
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page.
Other sources
It was found that application for listing of system groups in Red Hat Network Satellite Server and Spacewalk services did not properly HTML escape the content of QueryString. A remote attacker could use this flaw to conduct XSS attacks, potentially leading into attacker's ability to steal the users' session cookie.
Acknowledgements:
Red Hat would like to thank Daniel Karanja Muturi for reporting this issue.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2919?
CVE-2011-2919 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2011-2919?
To fix CVE-2011-2919, update to the fixed versions of Spacewalk or Red Hat Satellite provided by Red Hat.
What impact does CVE-2011-2919 have on affected systems?
CVE-2011-2919 allows remote attackers to inject malicious scripts that could lead to unauthorized actions or data theft.
Which software versions are affected by CVE-2011-2919?
CVE-2011-2919 affects Red Hat Spacewalk version 1.6 and Red Hat Network Satellite.
Can CVE-2011-2919 be exploited by unauthenticated users?
Yes, CVE-2011-2919 can be exploited by unauthenticated remote attackers via manipulated query strings.