REDHAT-BUG-731647: Medium severity red hat satellite vulnerability
Published Aug 18, 2011
·Updated
A cross-site scripting flaw was discovered in the Lookup Login/Password form of the RHN Satellite and Spacewalk.
https://rhnhost/help/forgotpassword.pxt/%22onmouseover=alert%281%29%3E
Acknowledgements:
Red Hat would like to thank Sylvain Maes for reporting this issue.
Affected Software
2 affected components
Red Hat RHN Satellite
Red Hat Spacewalk
Event History
Aug 18, 2011
Data Sourced
via Red Hat·08:26 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-731647?
The severity of REDHAT-BUG-731647 is classified as medium due to its potential for cross-site scripting attacks.
2
How do I fix REDHAT-BUG-731647?
To fix REDHAT-BUG-731647, update to the latest versions of Red Hat RHN Satellite and Spacewalk that contain the security patch.
3
What products are affected by REDHAT-BUG-731647?
REDHAT-BUG-731647 affects Red Hat RHN Satellite and Red Hat Spacewalk.
4
What type of vulnerability is REDHAT-BUG-731647?
REDHAT-BUG-731647 is a cross-site scripting (XSS) vulnerability.
5
Is user input affected by REDHAT-BUG-731647?
Yes, user input in the Lookup Login/Password form is vulnerable in REDHAT-BUG-731647.