CVE-2014-3595: XSS
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3595?
CVE-2014-3595 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-3595?
To fix CVE-2014-3595, it is recommended to upgrade to a patched version of Spacewalk or Red Hat Satellite.
Who is affected by CVE-2014-3595?
CVE-2014-3595 affects users of Spacewalk versions 1.2.39, 1.7.54, 2.0.2, and Red Hat Satellite versions 5.4 to 5.6.
What can attackers do with CVE-2014-3595?
Attackers can exploit CVE-2014-3595 to inject arbitrary web scripts or HTML into vulnerable applications.
When was CVE-2014-3595 published?
CVE-2014-3595 was published on September 16, 2014.