First published: Wed Dec 07 2011(Updated: )
Red Hat Network (RHN) Satellite provides a solution to organizations<br>requiring absolute control over and privacy of the maintenance and package<br>deployment of their servers. It allows organizations to utilize the<br>benefits of the Red Hat Network without having to provide public Internet<br>access to their servers or other client systems.<br>A cross-site scripting (XSS) flaw was found in the RHN Satellite web<br>interface. An authenticated RHN Satellite user could use this flaw to<br>perform a cross-site scripting attack against other authenticated users who<br>are using the RHN Satellite web interface. (CVE-2011-4346)<br>Red Hat would like to thank William Hoffmann for reporting this issue.<br>Users of Red Hat Network Satellite 5.4.1 are advised to upgrade to these<br>updated packages, which contain a patch to correct this issue. For this<br>update to take effect, Red Hat Network Satellite must be restarted. Refer<br>to the Solution section for details.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/spacewalk-web | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-base | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-base-minimal | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-dobby | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-grail | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-html | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-pxt | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-sniglets | <1.2.7-21.el6 | 1.2.7-21.el6 |
redhat/spacewalk-web | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-base | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-base-minimal | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-dobby | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-grail | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-html | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-pxt | <1.2.7-21.el5 | 1.2.7-21.el5 |
redhat/spacewalk-sniglets | <1.2.7-21.el5 | 1.2.7-21.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.