CVE-2011-1594

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:network_satellite:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:spacewalk:1.6:*:*:*:*:*:*:*

History

02 Apr 2026, 22:16

Type Values Removed Values Added
Summary (en) Open redirect vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url_bounce parameter. (en) A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
CVSS v2 : 5.8
v3 : unknown
v2 : 5.8
v3 : 6.5
References
  • () https://access.redhat.com/security/cve/CVE-2011-1594 -
CWE CWE-601

21 Nov 2024, 01:26

Type Values Removed Values Added
References () http://www.redhat.com/support/errata/RHSA-2011-1299.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2011-1299.html - Patch, Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=672167 - Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=672167 - Vendor Advisory
References () https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html - () https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html -

Information

Published : 2014-02-05 18:55

Updated : 2026-04-02 22:16


NVD link : CVE-2011-1594

Mitre link : CVE-2011-1594

CVE.ORG link : CVE-2011-1594


JSON object : View

Products Affected

redhat

  • network_satellite
  • spacewalk
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-20

Improper Input Validation