CVE-2022-43754: SUMA/UYUNI reflected cross site scripting in /rhn/audit/scap/Search.do
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.2 allows remote attackers to embed Javascript code via /rhn/audit/scap/Search.do This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.2 hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.25.2, locale-formula-0.3-150300.3.3.2, py27-compat-salt-3000.3-150300.7.7.26.2, python-urlgrabber-3.10.2.1py23-150300.3.3.2, spacecmd-4.2.20-150300.4.30.2, spacewalk-backend-4.2.25-150300.4.32.4, spacewalk-client-tools-4.2.21-150300.4.27.3, spacewalk-java-4.2.43-150300.3.48.2, spacewalk-utils-4.2.18-150300.3.21.2, spacewalk-web-4.2.30-150300.3.30.3, susemanager-4.2.38-150300.3.44.3, susemanager-doc-indexes-4.2-150300.12.36.3, susemanager-docsen-4.2-150300.12.36.2, susemanager-schema-4.2.25-150300.3.30.3, susemanager-sls versions prior to 4.2.28. SUSE Linux Enterprise Module for SUSE Manager Server 4.3 spacewalk-java versions prior to 4.3.39. SUSE Manager Server 4.2 release-notes-susemanager versions prior to 4.2.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
spacewalk-backendto a version that resolves this vulnerability.Fixed in 4.2.25-150300.4.32.4 - Upgrade
Upgrade
spacewalk-client-toolsto a version that resolves this vulnerability.Fixed in 4.2.21-150300.4.27.3 - Upgrade
Upgrade
spacewalk-javato a version that resolves this vulnerability.Fixed in 4.2.43-150300.3.48.2 - Upgrade
Upgrade
spacewalk-webto a version that resolves this vulnerability.Fixed in 4.2.30-150300.3.30.3 - Upgrade
Upgrade
spacewalk-utilsto a version that resolves this vulnerability.Fixed in 4.2.18-150300.3.21.2 - Upgrade
Upgrade
spacecmdto a version that resolves this vulnerability.Fixed in 4.2.20-150300.4.30.2 - Upgrade
Upgrade
susemanagerto a version that resolves this vulnerability.Fixed in 4.2.38-150300.3.44.3 - Upgrade
Upgrade
susemanager-doc-indexesto a version that resolves this vulnerability.Fixed in 4.2-150300.12.36.3 - Upgrade
Upgrade
susemanager-docs_ento a version that resolves this vulnerability.Fixed in 4.2-150300.12.36.2 - Upgrade
Upgrade
susemanager-schemato a version that resolves this vulnerability.Fixed in 4.2.25-150300.3.30.3 - Upgrade
Upgrade
susemanager-slsto a version that resolves this vulnerability.Fixed in 4.2.28 - Upgrade
Upgrade
hub-xmlrpc-api-0.7to a version that resolves this vulnerability.Fixed in 0.7-150300.3.9.2 - Upgrade
Upgrade
inter-server-syncto a version that resolves this vulnerability.Fixed in 0.2.4-150300.8.25.2 - Upgrade
Upgrade
locale-formulato a version that resolves this vulnerability.Fixed in 0.3-150300.3.3.2 - Upgrade
Upgrade
py27-compat-saltto a version that resolves this vulnerability.Fixed in 3000.3-150300.7.7.26.2 - Upgrade
Upgrade
python-urlgrabberto a version that resolves this vulnerability.Fixed in 3.10.2.1py2_3-150300.3.3.2 - Upgrade
Upgrade
spacewalk-javato a version that resolves this vulnerability.Fixed in 4.3.39 - Upgrade
Upgrade
release-notes-susemanagerto a version that resolves this vulnerability.Fixed in 4.2.10
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43754.
What is the severity of CVE-2022-43754?
The severity of CVE-2022-43754 is medium (5.4).
Which software versions are affected by CVE-2022-43754?
CVE-2022-43754 affects SUSE Manager Server 4.2 (up to version 4.2.10), SUSE Manager Server 4.3 (up to version 4.3.2), and Uyuni-project Uyuni (up to version 2022.10).
What is the description of CVE-2022-43754?
CVE-2022-43754 is an 'Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)' vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, and SUSE Manager Server 4.2.
How can I fix CVE-2022-43754?
To fix CVE-2022-43754, apply the necessary security patches provided by the vendor.