First published: Wed Sep 28 2011(Updated: )
A cross-site scripting (XSS) flaw was found in the way the 'System Details' => 'Details' => 'Custom Info' page of the Red Hat Network Satellite web interface sanitized value (the Description field) of the asset tag / key, assigned to the particular system, created via 'Custom System Info' page. An authenticated Red Hat Network Satellite user could use this flaw to execute arbitrary HTML or web script code via specially-crafted value for the asset 'Custom System Info' key. Acknowledgements: Red Hat would like to thank William Hoffmann for reporting this issue.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/spacewalk-web | <0:1.2.7-21.el5 | 0:1.2.7-21.el5 |
Redhat Satellite | =5.4.1 | |
Redhat Enterprise Linux | =5.0 | |
Redhat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.