A Cross-site scripting issue was discovered in RHN when searching software channels. This issue affects the live hosted RHN as well as Red Hat Network Satellite.
It was found that Red Hat Network (RHN) Satellite and Spacewalk services did not protect against Cross-Site Request Forgery (CSRF) attacks. If an authenticated RHN Satellite or Spacewalk service user visited a specially- crafted web page, it could lead to unauthorized command execution with the privileges of that user, for example, creating a new user account, granting administrator privileges to user accounts, disabling the account of the current user, and so on.
Acknowledgements:
Red Hat would like to thank Christian Johansson of Bitsec AB and Thomas Biege of the SUSE Security Team for independently reporting this issue.