First published: Thu Aug 18 2011(Updated: )
A cross-site scripting flaw was discovered in the Lookup Login/Password form of the RHN Satellite and Spacewalk. <a href="https://rhnhost/help/forgot_password.pxt/%22onmouseover=alert%281%29%3E">https://rhnhost/help/forgot_password.pxt/%22onmouseover=alert%281%29%3E</a> Acknowledgements: Red Hat would like to thank Sylvain Maes for reporting this issue.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite | ||
Red Hat Spacewalk | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3344 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2011-3344, update Red Hat Satellite or Red Hat Spacewalk to a version that addresses this vulnerability.
CVE-2011-3344 affects Red Hat Satellite and Red Hat Spacewalk version 1.6.
CVE-2011-3344 is a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form.
CVE-2011-3344 can allow attackers to execute arbitrary JavaScript in the context of users' browsers, potentially compromising user data.