A cross-site scripting flaw was discovered in the Lookup Login/Password form of the RHN Satellite and Spacewalk.
https://rhnhost/help/forgotpassword.pxt/%22onmouseover=alert%281%29%3E
Acknowledgements:
Red Hat would like to thank Sylvain Maes for reporting this issue.
It was found that application for listing of system groups in Red Hat Network Satellite Server and Spacewalk services did not properly HTML escape the content of QueryString. A remote attacker could use this flaw to conduct XSS attacks, potentially leading into attacker's ability to steal the users' session cookie.
Acknowledgements:
Red Hat would like to thank Daniel Karanja Muturi for reporting this issue.
Open redirect vulnerability in Red Hat Network Satellite and Spacewalk software content management services allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the urlbounce parameter.
Acknowledgements:
Red Hat would like to thank Thomas Biege of the SuSE Security Team for reporting this issue.
A session fixation flaw was found in the way Red Hat Network (RHN) Satellite and Spacewalk services handled session cookies. An RHN Satellite or Spacewalk Server user able to pre-set the session cookie in a victim's browser to a valid value could use this flaw to hijack the victim's session after the next log in.
References: [1] http://en.wikipedia.org/wiki/Sessionfixation [2] http://shiflett.org/articles/session-fixation
Acknowledgements:
Red Hat would like to thank Thomas Biege of the SuSE Security Team for reporting this issue.
It was found that Red Hat Network (RHN) Satellite and Spacewalk services did not protect against Cross-Site Request Forgery (CSRF) attacks. If an authenticated RHN Satellite or Spacewalk service user visited a specially- crafted web page, it could lead to unauthorized command execution with the privileges of that user, for example, creating a new user account, granting administrator privileges to user accounts, disabling the account of the current user, and so on.
Acknowledgements:
Red Hat would like to thank Christian Johansson of Bitsec AB and Thomas Biege of the SUSE Security Team for independently reporting this issue.